8.8High
CVE-2026-90357
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement The flow is added to dev->twt_list before sending the agreement to the firmware, but the error path leaves it linked while flowid_mask is never set. The flow slot can then be reused and memset while still on the list, corrupting twt_list, and station removal leaves a dangling entry behind that mt7915_mac_twt_sched_list_add() later walks.
What this means for your business
- An attacker can use it from inside the same network, without a login, and without anyone at your company clicking anything.
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 8.8 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-09-17
- Last modified
- 2026-09-18
- Sources
- NVD
References
- https://git.kernel.org/stable/c/16a04441eab0dcd4d7126a6f66b370adbf28f96d
- https://git.kernel.org/stable/c/1bd5c4ed2b9045faf83315c54cd37a9b7c71b5c7
- https://git.kernel.org/stable/c/6bce0f1280c94af8314f895f404629da09f0788c
- https://git.kernel.org/stable/c/beaa42b875965dbc3e80e46970e0bfa60a94c2db
- https://git.kernel.org/stable/c/c09d1b15ed2dc49060303b16a296b7b8b7794cbe
- https://git.kernel.org/stable/c/cabe239e95b4eebf5b6c3654087b66ff9425bc7b