7.8

CVE-2026-89523

wifi: mt76: mt7925: cancel pending mlo_pm_work

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: cancel pending mlo_pm_work

If the device is reset, suspended or unregistered within that window,
the pending work can still run and access vif/bss data that may already
be freed, or send MCU commands while the firmware is not available.

Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown
and suspend paths:

 - mt7925_mac_reset_work()        (chip reset recovery)
 - mt7925e_unregister_device()    (PCIe unbind)
 - mt7925_pci_suspend()           (PCIe bus suspend)
 - mt7925_suspend()               (mac80211 suspend)
 - mt7925u_suspend()              (USB bus / runtime suspend)

This ensures the work is stopped before the device state becomes
invalid.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 276a568832577c81ec90b62dc506bbdc3781ca46
Version < 5be6d02837d418bc6c805b5cab1b338de6de9ca7
Status affected
Version 276a568832577c81ec90b62dc506bbdc3781ca46
Version < c5e073f2fbfd34d22099a50d96f60990799753e2
Status affected
Version 276a568832577c81ec90b62dc506bbdc3781ca46
Version < 2889e84282dda147f10b10d94cf0efd90a349c53
Status affected
Version 74eb79258bfd5f2ffe6d26a09c898992b2afa1ce
Status affected
Version 6.14.3
Version < 6.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5be6d02837d418bc6c805b5cab1b338de6de9ca7
https://git.kernel.org/stable/c/c5e073f2fbfd34d22099a50d96f60990799753e2
https://git.kernel.org/stable/c/2889e84282dda147f10b10d94cf0efd90a349c53