---
id: CVE-2026-90355
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mt76: mt7996: clear stale link state on full reset

  After a full chip reset, mac80211 reconfig replays interface, link and
  channel context setup
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mt76: mt7996: clear stale link state on full reset

  After a full chip reset, mac80211 reconfig replays interface, link and
  channel context setup. mt7996_vif_link_…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= ace5d3b6b49e8391beb4d7244348ba7da5298878 <
    fc3762724a36867c1749233c43368c2637ecf029
  - >-
    Linux >= ace5d3b6b49e8391beb4d7244348ba7da5298878 <
    75d2a4e2129b58bb0ddb842387299038495aad2a
  - Linux 6.18
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:34.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90355'
references:
  - url: 'https://git.kernel.org/stable/c/75d2a4e2129b58bb0ddb842387299038495aad2a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fc3762724a36867c1749233c43368c2637ecf029'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.813Z'
epss: 0.00189
epssPercentile: 0.08852
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: clear stale link state on full reset

After a full chip reset, mac80211 reconfig replays interface, link and
channel context setup. mt7996_vif_link_add() short-circuits when the
link_id is still marked in mvif->valid_links, a state introduced for
postponing link teardown to interface removal. The reset path frees the
link structures without clearing those bits, so the replayed setup never
re-creates dev_info/bss_info/STA records in the restarted firmware and
never re-registers the link wcid, leaving the device inoperative.

The reset path also leaks every allocated MLD index: per-link indices
and the per-vif group/remap indices are re-allocated from scratch during
reconfig, but the old bits stay set in the masks, so repeated full
resets exhaust the index space.

Clear valid_links in the reset vif iterator and reset the MLD index
masks alongside the existing omac_mask clearing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
