CVE-2026-90353

Source
https://cve.org/CVERecord?id=CVE-2026-90353
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90353.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90353
Downstream
Published
2026-09-17T16:09:00Z
Modified
2026-09-18T03:48:37Z
Summary
wifi: mt76: mt7915: fix ext PHY use-after-free on register error path
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: fix ext PHY use-after-free on register error path

After mt7915_register_ext_phy() succeeded, a failure of the main PHY mt7915_init_debugfs() or mt7915_coredump_register() unwound through free_phy2, which called ieee80211_free_hw() on the ext PHY hw while it was still registered with mac80211, since mt76_unregister_device() only unregisters the main hw. Unregister the ext PHY (thermal + phy + hw) first and skip the redundant free.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90353.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7b8e1ae886e45aed9274048f2836a70b75ecfa40
Fixed
aa55bec92ba7747dd08feff409f8074c5e052e71
Fixed
ad706fcf6255494613b94418e7243d98065dbeaf
Fixed
34058ad122f7524e33df8e38caba4b1d803b025a
Fixed
a7fd3bae8e11a7c00df6a5021d9ef248ae9f9bf5
Fixed
648f5f03ff50d4bd719106ace0cdf1d8be02cbdd
Fixed
15b960014f24dce5388d4a2e7274e6490cb3c421

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90353.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90353.json"