Bug 2536746 (CVE-2026-90354) - CVE-2026-90354 kernel: wifi: mt76: mt7915: fix double hif2 init on the non-WED path
Summary: CVE-2026-90354 kernel: wifi: mt76: mt7915: fix double hif2 init on the non-WE...
Keywords:
Status: NEW
Alias: CVE-2026-90354
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 19:24 UTC by OSIDB Bzimport
Modified: 2026-10-05 13:34 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-17 19:24:02 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: fix double hif2 init on the non-WED path

mt7915_pci_init_hif2() was called unconditionally and again inside the
WED-inactive branch. The helper increments the global hif_idx, writes the
PCIe RECOG_ID register and takes a get_device() reference via
mt7915_pci_get_hif2(), while removal only drops one reference. On non-WED
dual-hif hardware this double-incremented hif_idx, wrote RECOG_ID twice and
leaked a device reference. Only the call inside the WED-inactive branch is
correct; drop the unconditional one. hif2 is already initialised to NULL.


Note You need to log in before you can comment on or make changes to this bug.