CVE-2026-90366
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV When a CSA countdown is active, mt7996_mcu_beacon_cntdwn() emits two bss_bcn_cntdwn_tlv entries (the CSA countdown and the CCA-abort BCC), but MT7996_BEACON_UPDATE_SIZE only reserved one. With MBSSID enabled and a near-maximum beacon template the extra 8 bytes could push the offload command past MT7996_MAX_BSS_OFFLOAD_SIZE and trigger skb_over_panic(). Reserve room for both countdown TLVs.
Is your site exposed to CVE-2026-90366?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/1a51aff0e048dc5b8252d65808b79939c942d6ec
https://git.kernel.org/stable/c/1d348f96623ec20d700af7d4dfc00a74da6238ac
https://git.kernel.org/stable/c/45d8896e4cffffb2c6554ccbec6efe7a0d53166f
https://git.kernel.org/stable/c/50c66bab321140c49aa2ed779a3ec9d2f085b458
https://git.kernel.org/stable/c/bc1d694a1ffe0062c3adf0db1d64ad54454398ec
Frequently Asked Questions
What is CVE-2026-90366? +
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV
When a CSA countdown is active, mt7996_mcu_beacon_cntdwn() emits two
bss_bcn_cntdwn_tlv entries (the CSA countdown and the CCA-abort BCC), but
MT7996_BEACON_UPDATE_SIZE only reserved one. With MBSSID enabled and a
near-maximum beacon template the extra 8 bytes could push the offload
command past MT7996_MAX_BSS_OFFLOAD_SIZE and trigger skb_over_panic().
Reserve room for both countdown TLVs.
How do I check if I'm vulnerable to CVE-2026-90366? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.