CVE-2026-68309: wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: connac: fix possible NULL-pointer deref in mt76connacmcuunibsshetlv()
mt76connacgethephycap routine can theoretically return NULL so check cap pointer before dereferencing it.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.150.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68309?
CVE-2026-68309 has a risk score of 16, indicating a critical vulnerability.
How do I fix CVE-2026-68309?
To fix CVE-2026-68309, update your Linux kernel to the latest version that includes the patch for this vulnerability.
What systems are affected by CVE-2026-68309?
CVE-2026-68309 affects systems running the affected versions of the Linux kernel with the mt76: connac wireless drivers.
What kind of exploitation is possible with CVE-2026-68309?
CVE-2026-68309 can potentially lead to a NULL-pointer dereference, which may cause system instability or crashes.
When was CVE-2026-68309 published?
CVE-2026-68309 was published on August 10, 2026.