CVE-2026-90376

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP Problem: MCU command timeout while the firmware state is normal, and the firmware keeps showing the error log "ERROR!! NO PAUSE...". Root cause: If the MLD_ID field in the TXD is neither the primary link id nor the secondary link id, it may lead to a firmware busy loop when the third link is in power saving mode. Remap frames directed to a third link to the primary link wcid. Since TX status events and txfree completions carry the wcid the firmware saw, use the remapped wcid for packet id tracking and non-AQL packet accounting as well, while the frame keeps its original link context for addressing, band and OMAC selection.

Package Linux Kernel
Published 2026-09-17
Last modified 2026-09-17
Patch available
Yes

Affected versions

Linux kernel versions 6.18.33, 6.19 and later are affected. Fixed in 6.18.52, 7.2.6, 7.3-rc1 and their respective stable series.

Affected from
≥ 6.18.33 ≥ 6.19
Fixed in
✓ 6.18.52 6.18.x ✓ 7.2.6 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-90376?

    CVE-2026-90376 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.18.33 onward and has been patched in 6.18.52, 7.2.6 and 7.3-rc1. CVE-2026-90376 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-90376?

    Yes. CVE-2026-90376 has been patched. Fixed versions include 6.18.52, 7.2.6 and 7.3-rc1. If you are running Linux kernel 6.18.33 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-90376 actively exploited?

    No. CVE-2026-90376 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.