wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
Published Sep 17, 2026
8.8
HIGHCVSS 3.1
EPSS 0.38%
Description
mt7996_mac_reset_work() parked the tx worker and disabled the RX/TX NAPIs before taking dev->mt76.mutex. mt76_worker_disable()/_enable() are plain kthread park/unpark, not refcounted, and __mt76_set_channel() toggles the same worker and the MT76_RESET bit under the mutex. An L1 SER racing a channel switch could therefore have the worker unparked and MT76_RESET cleared while the reset path resets the DMA rings, corrupting descriptors or tokens. Take the mutex before disabling the worker, as mt7915 does.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.4
- Version 6.18.52StatusunaffectedConstraints<=6.18.*
- Version 7.2.6StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82028 Advisory
- https://git.kernel.org/stable/c/594c4b7f89f9ea75dc9c50b5e4c4296db4a3d701
- https://git.kernel.org/stable/c/6190db312b8230813f529f014b26247c6d9800d0
- https://git.kernel.org/stable/c/906ad486ba5c4933d82e1ebe0685656390a48450
Change history (0)
No recorded changes yet.