๐Ÿ” CVE Alert

CVE-2026-53097

UNKNOWN 0.0

wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() When the mt7996 pci chip is detaching, the mt7996_crash_data is released in mt7996_coredump_unregister(). However, the work item dump_work may still be running or pending, leading to UAF bugs when the already freed crash_data is dereferenced again in mt7996_mac_dump_work(). The race condition can occur as follows: CPU 0 (removal path) | CPU 1 (workqueue) mt7996_pci_remove() | mt7996_sys_recovery_set() mt7996_unregister_device() | mt7996_reset() mt7996_coredump_unregister() | queue_work() vfree(dev->coredump.crash_data) | mt7996_mac_dump_work() | crash_data-> // UAF Fix this by ensuring dump_work is properly canceled before the crash_data is deallocated. Add cancel_work_sync() in mt7996_unregister_device() to synchronize with any pending or executing dump work.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
878161d5d4a469a6ef7f3fb4fe9f676bc508ee99 < 180182a3f23ff79430a32ca2c4c1885368ceab48 878161d5d4a469a6ef7f3fb4fe9f676bc508ee99 < aa4a31cd89f4fde5043ac613fe0e27014a60a60b 878161d5d4a469a6ef7f3fb4fe9f676bc508ee99 < 188e10f9ea3109d23c6b7643aa6ec2f5cb0faa6d 878161d5d4a469a6ef7f3fb4fe9f676bc508ee99 < c8f62f73bbced3a79894655bdb0b625462d956fc
Linux / Linux
6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/180182a3f23ff79430a32ca2c4c1885368ceab48 git.kernel.org: https://git.kernel.org/stable/c/aa4a31cd89f4fde5043ac613fe0e27014a60a60b git.kernel.org: https://git.kernel.org/stable/c/188e10f9ea3109d23c6b7643aa6ec2f5cb0faa6d git.kernel.org: https://git.kernel.org/stable/c/c8f62f73bbced3a79894655bdb0b625462d956fc