CVE-2026-90382
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length The MPDU length in the rx descriptor comes from the hardware. In monitor mode with the fcsfail filter enabled, the hardware passes up corrupted frames, and a corrupted frame can report a length larger than the received buffer. The bounds check correctly discards such frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage frame taints the kernel, and panics it on the first such frame when panic_on_warn is set. Drop the WARN and discard the frame silently, matching what commit c2d4c8723dbf ("mt76x2: remove some harmless WARN_ONs in tx status and rx path") did for the neighboring rx and tx status paths. Observed immediately on rx with an MT7612U in fcsfail monitor mode on a busy channel.
What this means for your business
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- Not yet scored
- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-09-17
- Last modified
- 2026-09-17
- Sources
- NVD
References
- https://git.kernel.org/stable/c/17d6b89e09eac2d90272fceeba3644e92212e02f
- https://git.kernel.org/stable/c/2d31e332c13b1db7745a7bd9cf74bc105524bcac
- https://git.kernel.org/stable/c/61b1f6d92249bc34580ff19de7c69c805f82adca
- https://git.kernel.org/stable/c/6def491fe9c4e83aa8cba62d74e9d4ab751ee967
- https://git.kernel.org/stable/c/81497634d9f872fd3e8b03aada55574afff6f174
- https://git.kernel.org/stable/c/b6e7958602bd1acdb8ae92703b6689a28bcc9bc0
- https://git.kernel.org/stable/c/c65bbfc730df9ebf0fea8e286b0ad2dfab03dbfe
- https://git.kernel.org/stable/c/d55e7aede542c4c76ead82d37d0c112f21eb2ac2