Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: cancel pending mlo_pm_work

If the device is reset, suspended or unregistered within that window,
the pending work can still run and access vif/bss data that may already
be freed, or send MCU commands while the firmware is not available.

Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown
and suspend paths:

- mt7925_mac_reset_work() (chip reset recovery)
- mt7925e_unregister_device() (PCIe unbind)
- mt7925_pci_suspend() (PCIe bus suspend)
- mt7925_suspend() (mac80211 suspend)
- mt7925u_suspend() (USB bus / runtime suspend)

This ensures the work is stopped before the device state becomes
invalid.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to kernel memory corruption or crash
Action: Patch
AI Analysis

Impact

The vulnerability is a classic Use-After-Free flaw (CWE-367) in the mt76 WiFi driver for the MT7925 chipset. When the device is reset, suspended, or unbound while the delayed work item mlo_pm_work is pending, the work function runs and accesses freed vif/bss structures or attempts to talk to firmware that is no longer present. This can corrupt kernel memory or cause a kernel panic, resulting in a loss of system availability.

Affected Systems

All Linux kernel builds that include the mt76 driver with support for the MT7925 chipset are vulnerable until the patch that adds cancel_delayed_work_sync(&dev reset, unregister, and suspend paths is applied. Any kernel version prior to the commit that fixes this path is affected, regardless of the specific release level, as the vulnerability is tied to the driver code rather than a particular kernel minor version.

Risk and Exploitability

The CVSS score of 7.8 reflects significant severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it is not actively exploited in the wild. An attacker requires local or privileged access that allows triggering a device reset, suspend, or unplug event; from there, the use‑after‑free can lead to a kernel crash or memory corruption, potentially enabling further compromise. The likely attack vector is therefore local or privileged, as no remote exploitation path is described in the input.

Generated by OpenCVE AI on September 15, 2026 at 06:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the mt76 driver_work_sync calls in reset, unregister, and suspend paths.
  • Reboot the system after applying the kernel update to ensure all pending work items are cleared and firmware state is reset.
  • If a kernel upgrade is not immediately possible, prevent the MT7925 device from being reset or suspended by disabling the mt76 module or configuring the system to keep the device online, thereby averting the use‑After‑Free condition.

Generated by OpenCVE AI on September 15, 2026 at 06:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel pending mlo_pm_work If the device is reset, suspended or unregistered within that window, the pending work can still run and access vif/bss data that may already be freed, or send MCU commands while the firmware is not available. Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown and suspend paths: - mt7925_mac_reset_work() (chip reset recovery) - mt7925e_unregister_device() (PCIe unbind) - mt7925_pci_suspend() (PCIe bus suspend) - mt7925_suspend() (mac80211 suspend) - mt7925u_suspend() (USB bus / runtime suspend) This ensures the work is stopped before the device state becomes invalid.
Title wifi: mt76: mt7925: cancel pending mlo_pm_work
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:30:22.235Z

Reserved: 2026-09-11T19:38:34.718Z

Link: CVE-2026-89523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:35.010

Modified: 2026-09-13T07:17:14.697

Link: CVE-2026-89523

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:04Z

Links: CVE-2026-89523 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T06:15:13Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition