CVE-2026-68310

critical

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: guard HE capability lookups mt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after checking HE support, then dereference the HE PHY capability returned by mt76_connac_get_he_phy_cap(). That helper can return NULL when no capability entry matches the vif type. Fetch the capability before appending the TLV and skip the HE-specific setup when no matching capability is available.

References

https://git.kernel.org/stable/c/a031f454f14e3e76ad03bcb23918e1a82b4b0869

https://git.kernel.org/stable/c/8e9db062654a388d0fa587acbeeae68dd33eba41

https://git.kernel.org/stable/c/8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67

https://git.kernel.org/stable/c/871549814eb4da081f1e93cc0c7ea626a310a966

https://git.kernel.org/stable/c/6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e

https://git.kernel.org/stable/c/23a2b98e754da04e0e90314d5fa8ca44349590fb

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-19

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00168