-
CVE-2026-80825
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:54:29
- Zuletzt bearbeitet 04.09.2026 16:18:10
- Erkennungen
wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB
header onto every skb and assumes the headroom for them is already
there. That holds for locally generated traffic, where mac80211
reserves hw->extra_tx_headroom, but forwarded frames are sent through
ieee80211_8023_xmit(), which does not reserve it. Bridge a wired
interface to an mt7925u AP and the first forwarded frame that arrives
short panics the kernel:
skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1
kernel BUG at net/core/skbuff.c:212!
Call trace:
skb_panic+0x58/0x60 (P)
skb_push+0x58/0x60
mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common]
mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb]
__mt76_tx_queue_skb+0x54/0xe8 [mt76]
mt76_txq_schedule.part.0+0x204/0x478 [mt76]
mt76_txq_schedule_all+0x50/0x80 [mt76]
mt792x_tx_worker+0x68/0x100 [mt792x_lib]
__mt76_worker_fn+0x84/0x150 [mt76]
Whether a given setup hits it depends on how much headroom the ingress
netdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging
onboard ethernet to a Netgear A9000; originally reported on an MT7986
router running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet),
which leaves more headroom, helped narrow the trigger to the ingress
path.
The same bug was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76:
mt7921: don't assume adequate headroom for SDIO headers"), but mt7925
was copied from mt7921 without the fix. Add the same guard here.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
c948b5da6bbec742b433138e3e3f9537a85af2e5
Version <
9a72b180f0575e41471e088e09bddc4b73d6dee2
Status
affected
Version
c948b5da6bbec742b433138e3e3f9537a85af2e5
Version <
22edb6786127271aeba7abd30f152977c605c6a3
Status
affected
Version
c948b5da6bbec742b433138e3e3f9537a85af2e5
Version <
8d481f93588932a95f657671d4e1601b90d130cc
Status
affected
Version
c948b5da6bbec742b433138e3e3f9537a85af2e5
Version <
e5e8fc11a7ac578f16079f855b7fffc1649d053c
Status
affected
Version
c948b5da6bbec742b433138e3e3f9537a85af2e5
Version <
ef3e34874d2332d0f63e72c2c35ce5c93568c125
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.7
Status
affected
Version
0
Version <
6.7
Status
unaffected
Version <=
6.12.*
Version
6.12.108
Status
unaffected
Version <=
6.18.*
Version
6.18.49
Status
unaffected
Version <=
7.1.*
Version
7.1.13
Status
unaffected
Version <=
7.2.*
Version
7.2.3
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/9a72b180f0575e41471e088e09bddc4b73d6dee2
https://git.kernel.org/stable/c/22edb6786127271aeba7abd30f152977c605c6a3
https://git.kernel.org/stable/c/8d481f93588932a95f657671d4e1601b90d130cc
https://git.kernel.org/stable/c/e5e8fc11a7ac578f16079f855b7fffc1649d053c
https://git.kernel.org/stable/c/ef3e34874d2332d0f63e72c2c35ce5c93568c125