CVE-2026-90357

Source
https://cve.org/CVERecord?id=CVE-2026-90357
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90357.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90357
Downstream
Published
2026-09-17T16:09:02Z
Modified
2026-09-19T03:47:26Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement

The flow is added to dev->twt_list before sending the agreement to the firmware, but the error path leaves it linked while flowid_mask is never set. The flow slot can then be reused and memset while still on the list, corrupting twt_list, and station removal leaves a dangling entry behind that mt7915_mac_twt_sched_list_add() later walks.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90357.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3782b69d03e714b8ff98b84c7426d8cef0e64d7c
Fixed
c09d1b15ed2dc49060303b16a296b7b8b7794cbe
Fixed
1bd5c4ed2b9045faf83315c54cd37a9b7c71b5c7
Fixed
cabe239e95b4eebf5b6c3654087b66ff9425bc7b
Fixed
6bce0f1280c94af8314f895f404629da09f0788c
Fixed
beaa42b875965dbc3e80e46970e0bfa60a94c2db
Fixed
16a04441eab0dcd4d7126a6f66b370adbf28f96d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90357.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90357.json"