CVE-2026-90382
CVE CVE-2026-90382EUVD EUVD-2026-82043Published 2026-09-17T16:09:19.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length The MPDU length in the rx descriptor comes from the hardware. In monitor mode with the fcsfail filter enabled, the hardware passes up corrupted frames, and a corrupted frame can report a length larger than the received buffer. The bounds check correctly discards such frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage frame taints the kernel, and panics it on the first such frame when panic_on_warn is set. Drop the WARN and discard the frame silently, matching what commit c2d4c8723dbf ("mt76x2: remove some harmless WARN_ONs in tx status and rx path") did for the neighboring rx and tx status paths. Observed immediately on rx with an MT7612U in fcsfail monitor mode on a busy channel.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; patch: 6.1.188; patch: 7.3-rc1; 7bc04215a66b60e198aecaee8418f6d79fa19faa <d55e7aede542c4c76ead82d37d0c112f21eb2ac2; patch: 7.2.6; 4.16; 7bc04215a66b60e198aecaee8418f6d79fa19faa <6def491fe9c4e83aa8cba62d74e9d4ab751ee967; 7bc04215a66b60e198aecaee8418f6d79fa19faa <17d6b89e09eac2d90272fceeba3644e92212e02f; 7bc04215a66b60e198aecaee8418f6d79fa19faa <81497634d9f872fd3e8b03aada55574afff6f174; patch: 6.6.157; patch: 6.18.52; 7bc04215a66b60e198aecaee8418f6d79fa19faa <c65bbfc730df9ebf0fea8e286b0ad2dfab03dbfe; patch: 5.15.221; patch: 5.10.270; 7bc04215a66b60e198aecaee8418f6d79fa19faa <b6e7958602bd1acdb8ae92703b6689a28bcc9bc0; 7bc04215a66b60e198aecaee8418f6d79fa19faa <61b1f6d92249bc34580ff19de7c69c805f82adca; patch: 6.12.110; 7bc04215a66b60e198aecaee8418f6d79fa19faa <2d31e332c13b1db7745a7bd9cf74bc105524bcac
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.