{"id":"CVE-2026-90373","summary":"wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear\n\nmt7915_remove_interface() cleared the wcid mask bit with no lock held and\nbefore clearing the RCU wcid pointer. The mask is a non-atomic RMW shared\nwith the allocators, which all run under dev-\u003emt76.mutex; on DBDC the two\nwiphys share one mt76_dev, so this raced add_interface/sta_add on the\nother band and could leak or double-hand-out a wcid. Clearing the bit\nbefore the RCU pointer also let a concurrent allocation reuse the index\nand publish its wcid, which the subsequent NULL assignment then wiped.\nMove the clear into the existing mutex section, after the RCU pointer is\ncleared.","modified":"2026-09-19T03:47:29.047198797Z","published":"2026-09-17T16:09:13.368Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90373.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/5dce25f1d609ba991a9c22c27be586c92f03ed77"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b4a41a47a67c788e6b0625fa517ec8872e99bb6c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90373.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90373"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f3049b88b2b32326df97461813ae73e8bbc296fc"},{"fixed":"5dce25f1d609ba991a9c22c27be586c92f03ed77"},{"fixed":"b4a41a47a67c788e6b0625fa517ec8872e99bb6c"},{"fixed":"a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b"},{"fixed":"6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90373.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.12.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90373.json"}}],"schema_version":"1.9.0"}