Junglewise Threat Intelligence

CVE-2026-90350: Linux kernel mt76 out-of-bounds array access in mt76_vif_link()

CVE-2026-90350 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The mt76 wireless driver in the Linux kernel contains an out-of-bounds array access vulnerability in the mt76_vif_link() function. The function fails to validate link IDs before accessing an array, potentially reading past array boundaries and corrupting adjacent kernel memory. This could be triggered during WiFi operations and lead to kernel crashes or unpredictable behavior.

Technical details

The vulnerability is a classic out-of-bounds array read in the mt76_vif_link() function (drivers/net/wireless/mediatek/mt76/mt76.h). The function indexes mvif->link[] without validating the link_id parameter, but callers pass mvif->deflink_id or msta->deflink_id which hold IEEE80211_LINK_UNSPECIFIED (0xf) until the first link has been added. Since IEEE80211_MLD_MAX_NUM_LINKS is 15, an unvalidated link_id of 0xf reads one element past the array boundary, aliasing mt76_vif_data.offchannel_link. The vulnerability is reachable via mt7996_set_tsf(), mt7996_offset_tsf(), and mt7996_net_fill_forward_path() functions. The fix adds a bounds check that returns NULL for out-of-range link IDs, matching the pattern already used in mt7996_sta_link() and mt7996_sta_link_protected().

Affected products

  • Linux Linux kernel 4.x through 7.x (when mt76 Multi-Link Operation support was introduced)

Timeline

  • 2026-09-17: disclosed
  • 2026-08-01: patched: Original fix committed upstream (commit 9ba744a28c26eaa5cae930688a22e01888395308)

References

Related threats