CVE-2026-90376

Source
https://cve.org/CVERecord?id=CVE-2026-90376
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90376.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90376
Downstream
Published
2026-09-17T16:09:15Z
Modified
2026-09-18T03:48:37Z
Summary
wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP

Problem: MCU command timeout while the firmware state is normal, and the firmware keeps showing the error log "ERROR!! NO PAUSE...".

Root cause: If the MLD_ID field in the TXD is neither the primary link id nor the secondary link id, it may lead to a firmware busy loop when the third link is in power saving mode.

Remap frames directed to a third link to the primary link wcid. Since TX status events and txfree completions carry the wcid the firmware saw, use the remapped wcid for packet id tracking and non-AQL packet accounting as well, while the frame keeps its original link context for addressing, band and OMAC selection.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90376.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d6f6b3a65660d183ef33f5a6582fd3b47174fe5a
Fixed
5183b9f092fc0041618f38f895bd0ad860c26ca9
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
85cd5534a3f2ec93e7d88713a77df5b4255520df
Fixed
0a951ff6704db7b46c3f6d03b77e6053122be8ab
Fixed
ce35ecffc96e6d097d27b6fe30677a2cfe2e0461
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.18.33
Fixed
6.18.52

Affected versions

v6.*
v6.18.33
v6.18.34
v6.18.35
v6.18.36
v6.18.37
v6.18.38
v6.18.39
v6.18.40
v6.18.41
v6.18.42
v6.18.43
v6.18.44
v6.18.45
v6.18.46
v6.18.47
v6.18.48
v6.18.49
v6.18.50
v6.18.51

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90376.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90376.json"