CVE-2026-68310

Source
https://cve.org/CVERecord?id=CVE-2026-68310
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68310.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68310
Downstream
Published
2026-08-10T12:02:44.917Z
Modified
2026-08-12T04:18:47.702863626Z
Summary
wifi: mt76: mt7915: guard HE capability lookups
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: guard HE capability lookups

mt7915mcubsshetlv() and mt7915mcustabfertlv() both run after checking HE support, then dereference the HE PHY capability returned by mt76connacgethephy_cap(). That helper can return NULL when no capability entry matches the vif type.

Fetch the capability before appending the TLV and skip the HE-specific setup when no matching capability is available.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68310.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e6d557a78b6016eee7b9cd6832343efd32cc0b27
Fixed
23a2b98e754da04e0e90314d5fa8ca44349590fb
Fixed
a031f454f14e3e76ad03bcb23918e1a82b4b0869
Fixed
871549814eb4da081f1e93cc0c7ea626a310a966
Fixed
6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e
Fixed
8e9db062654a388d0fa587acbeeae68dd33eba41

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68310.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68310.json"