CVE-2026-90374

Source
https://cve.org/CVERecord?id=CVE-2026-90374
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90374.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90374
Downstream
Published
2026-09-17T16:09:14Z
Modified
2026-09-18T03:48:37Z
Summary
wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]

band_idx comes from a 2-bit descriptor field (0-3) and was used directly to index dev->mt76.phys[] (size __MT_MAX_BAND == 3) and dereference the result. A corrupt or reserved descriptor value could index out of bounds or hit a NULL phy on parts with fewer bands. Reject invalid band indices, mirroring mt7996_rx_get_wcid().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90374.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
98686cd21624c75a043e96812beadddf4f6f48e5
Fixed
535091c587268cc783608642838a655d828eefdd
Fixed
0f53ece876e1f3bbb3e18f48afc4af1ee967b16c
Fixed
b1c5cf8903bec5476a2233b4e45287b9a2213e02
Fixed
2243778a5fae8329ab5f18e7adcd7e03b911a1b7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90374.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90374.json"