Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: cancel mlo_pm_work on stop

mt7925 queues mlo_pm_work with a 5 second delay during multi-link
power-save setup and never cancels it on the stop path. If the device is
torn down inside that window, the work outlives the teardown and its timer
fires afterwards, trying to queue onto the workqueue that is already gone:

workqueue: cannot queue mt7925_mlo_pm_work [mt7925_common] on wq phy0
WARNING: kernel/workqueue.c:2283 at __queue_work+0x59/0xa0, CPU#1: swapper/1/0
call_timer_fn+0x2a/0x140
__run_timers+0x203/0x330
run_timer_softirq+0x86/0xf0

mt7921 already has its own stop callback, so add one for mt7925 that
cancels the work before calling mt792x_stop(). mt7925_ops backs both the
PCIe and USB drivers, so this covers both.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Exception (Potential Crash)
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the mt7925 wireless driver schedules a delayed work item, mlo_pm_work, during multi‑link power‑save initialization. The driver never cancels this work when the device is stopped. If the module is torn down within the five‑second window, the timer fires after the teardown, attempting to queue work onto a workqueue that has already been destroyed, producing a kernel warning and potentially causing a crash. This flaw is a resource‑management error, classified as CWE‑763: Information Leak Through Improper Safe Resource Release.

Affected Systems

All Linux kernel installations that include the mt7925 Wi‑Fi driver – both the PCIe and USB variants – are affected. The issue resides within the kernel’s wireless stack, specifically the mt76 subsystem; any hardware that ships with this driver bundled in the kernel image is impacted.

Risk and Exploitability

The CVSS score of 7.8 reflects a moderate severity. The EPSS score of <1% indicates a very low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it appears required to force the driver to stop during the five‑second delay window to trigger the fault; thus the practical attack surface is limited to an insider or attacker with physical or root access. No remote trigger or privilege‑elevation path exists, keeping the overall risk comparatively low.

Generated by OpenCVE AI on September 21, 2026 at 04:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that cancels mlo_pm_work before the device stops by upgrading to a kernel version that includes the fix.
  • If an immediate update is not possible, safely unload the mt7925 driver before removing the hardware to ensure no pending delayed work executes.
  • Alternatively, disable or reduce the multi‑link power‑save delay in driver configuration to avoid the timing window that triggers the fault.

Generated by OpenCVE AI on September 21, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7925 queues mlo_pm_work with a 5 second delay during multi-link power-save setup and never cancels it on the stop path. If the device is torn down inside that window, the work outlives the teardown and its timer fires afterwards, trying to queue onto the workqueue that is already gone: workqueue: cannot queue mt7925_mlo_pm_work [mt7925_common] on wq phy0 WARNING: kernel/workqueue.c:2283 at __queue_work+0x59/0xa0, CPU#1: swapper/1/0 call_timer_fn+0x2a/0x140 __run_timers+0x203/0x330 run_timer_softirq+0x86/0xf0 mt7921 already has its own stop callback, so add one for mt7925 that cancels the work before calling mt792x_stop(). mt7925_ops backs both the PCIe and USB drivers, so this covers both.
Title wifi: mt76: mt7925: cancel mlo_pm_work on stop
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:16.420Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:57.513

Modified: 2026-09-13T07:17:01.293

Link: CVE-2026-80936

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:10Z

Links: CVE-2026-80936 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses
  • CWE-763

    Release of Invalid Pointer or Reference