CVE-2026-90367 PUBLISHED

wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER

mt7996_mac_reset_work() parked the tx worker and disabled the RX/TX NAPIs before taking dev->mt76.mutex. mt76_worker_disable()/_enable() are plain kthread park/unpark, not refcounted, and __mt76_set_channel() toggles the same worker and the MT76_RESET bit under the mutex. An L1 SER racing a channel switch could therefore have the worker unparked and MT76_RESET cleared while the reset path resets the DMA rings, corrupting descriptors or tokens. Take the mutex before disabling the worker, as mt7915 does.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 27015b6fbcca836c6dbf196afc266e068af4aeec to 906ad486ba5c4933d82e1ebe0685656390a48450 (excl.)
  • affected from 27015b6fbcca836c6dbf196afc266e068af4aeec to 594c4b7f89f9ea75dc9c50b5e4c4296db4a3d701 (excl.)
  • affected from 27015b6fbcca836c6dbf196afc266e068af4aeec to 6190db312b8230813f529f014b26247c6d9800d0 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.4 is affected
  • unaffected from 0 to 6.4 (excl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References