Back

HIGH

wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER

Published Sep 17, 2026

Description

mt7996_mac_reset_work() parked the tx worker and disabled the RX/TX NAPIs before taking dev->mt76.mutex. mt76_worker_disable()/_enable() are plain kthread park/unpark, not refcounted, and __mt76_set_channel() toggles the same worker and the MT76_RESET bit under the mutex. An L1 SER racing a channel switch could therefore have the worker unparked and MT76_RESET cleared while the reset path resets the DMA rings, corrupting descriptors or tokens. Take the mutex before disabling the worker, as mt7915 does.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 17, 2026
Updated Sep 18, 2026
Reserved Sep 11, 2026
NVD
Status Received
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Linux
Published Sep 17, 2026
Updated Sep 18, 2026
Exploited since n/a
EUVD-2026-82028