{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89523","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.718Z","datePublished":"2026-09-11T19:44:04.796Z","dateUpdated":"2026-09-13T06:30:22.235Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:30:22.235Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: cancel pending mlo_pm_work\n\nIf the device is reset, suspended or unregistered within that window,\nthe pending work can still run and access vif/bss data that may already\nbe freed, or send MCU commands while the firmware is not available.\n\nAdd cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown\nand suspend paths:\n\n - mt7925_mac_reset_work()        (chip reset recovery)\n - mt7925e_unregister_device()    (PCIe unbind)\n - mt7925_pci_suspend()           (PCIe bus suspend)\n - mt7925_suspend()               (mac80211 suspend)\n - mt7925u_suspend()              (USB bus / runtime suspend)\n\nThis ensures the work is stopped before the device state becomes\ninvalid."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug leaves mlo_pm_work armed across local mt7925 teardown: chip-reset recovery, PCI unbind, and PCIe/mac80211/USB suspend. Those are host driver-lifecycle and power-management paths; over-the-air frames do not invoke them, matching other mt76 cleanup UAFs.\nAC:L - mt7925 queues mlo_pm_work with a fixed 5-second delay during MLO power-save setup. A local attacker who associates to a Wi-Fi 7 MLO AP and then immediately suspends, unbinds, or resets the device controls both sides and easily hits that window, with no attacker-uncontrollable race or heap layout.\nPR:L - MLO association uses nl80211 connect (GENL_UNS_ADMIN_PERM/CAP_NET_ADMIN). Logged-in users can then suspend via logind/polkit or Android autosleep, and NetworkManager/Android Wi-Fi controls expose this without init-namespace root, so privileges are Low.\nUI:N - The attacker performs MLO association and the subsequent suspend, PCI/USB unbind, or reset themselves. No separate victim action such as opening a file or mounting a filesystem is required.\nS:U - The use-after-free is of host kernel vif/bss_conf objects and the mt792x_dev-embedded delayed_work inside the mt7925 driver. It does not cross a VM, IOMMU, or sandbox security boundary.\nC:H - PCI/USB unbind runs ieee80211_unregister_hw, which destroys the phy workqueue, then mt76_free_device() frees the mt792x_dev that embeds mlo_pm_work while the 5s timer still points at them. The worker also dereferences vif/bss_conf that remove_interface or change_vif_links may already have freed, enabling disclosure via heap reclaim.\nI:H - The dangling delayed_work timer can fire on a freed mt792x_dev after unbind, and mt7925_mlo_pm_iter can send MCU BSS_INFO_UPDATE through stale mconf/vif objects. That is a classic timer/workqueue UAF exploitable for writes and control-flow hijack, so Integrity is High.\nA:H - The pending worker can WARN in __queue_work on a destroying phy workqueue, NULL-dereference a removed MLO link_conf, or issue MCU commands while firmware is reset or suspended, causing a kernel oops or panic. Any such crash is Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/mac.c","drivers/net/wireless/mediatek/mt76/mt7925/main.c","drivers/net/wireless/mediatek/mt76/mt7925/pci.c","drivers/net/wireless/mediatek/mt76/mt7925/usb.c"],"versions":[{"version":"276a568832577c81ec90b62dc506bbdc3781ca46","lessThan":"5be6d02837d418bc6c805b5cab1b338de6de9ca7","status":"affected","versionType":"git"},{"version":"276a568832577c81ec90b62dc506bbdc3781ca46","lessThan":"c5e073f2fbfd34d22099a50d96f60990799753e2","status":"affected","versionType":"git"},{"version":"276a568832577c81ec90b62dc506bbdc3781ca46","lessThan":"2889e84282dda147f10b10d94cf0efd90a349c53","status":"affected","versionType":"git"},{"version":"74eb79258bfd5f2ffe6d26a09c898992b2afa1ce","status":"affected","versionType":"git"},{"version":"6.14.3","lessThan":"6.15","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/mac.c","drivers/net/wireless/mediatek/mt76/mt7925/main.c","drivers/net/wireless/mediatek/mt76/mt7925/pci.c","drivers/net/wireless/mediatek/mt76/mt7925/usb.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5be6d02837d418bc6c805b5cab1b338de6de9ca7"},{"url":"https://git.kernel.org/stable/c/c5e073f2fbfd34d22099a50d96f60990799753e2"},{"url":"https://git.kernel.org/stable/c/2889e84282dda147f10b10d94cf0efd90a349c53"}],"title":"wifi: mt76: mt7925: cancel pending mlo_pm_work","x_generator":{"engine":"bippy-1.2.0"}}}}