๐Ÿ” CVE Alert

CVE-2026-80825

UNKNOWN 0.0

wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there. That holds for locally generated traffic, where mac80211 reserves hw->extra_tx_headroom, but forwarded frames are sent through ieee80211_8023_xmit(), which does not reserve it. Bridge a wired interface to an mt7925u AP and the first forwarded frame that arrives short panics the kernel: skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1 kernel BUG at net/core/skbuff.c:212! Call trace: skb_panic+0x58/0x60 (P) skb_push+0x58/0x60 mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common] mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb] __mt76_tx_queue_skb+0x54/0xe8 [mt76] mt76_txq_schedule.part.0+0x204/0x478 [mt76] mt76_txq_schedule_all+0x50/0x80 [mt76] mt792x_tx_worker+0x68/0x100 [mt792x_lib] __mt76_worker_fn+0x84/0x150 [mt76] Whether a given setup hits it depends on how much headroom the ingress netdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging onboard ethernet to a Netgear A9000; originally reported on an MT7986 router running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet), which leaves more headroom, helped narrow the trigger to the ingress path. The same bug was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76: mt7921: don't assume adequate headroom for SDIO headers"), but mt7925 was copied from mt7921 without the fix. Add the same guard here.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c948b5da6bbec742b433138e3e3f9537a85af2e5 < 9a72b180f0575e41471e088e09bddc4b73d6dee2 c948b5da6bbec742b433138e3e3f9537a85af2e5 < 22edb6786127271aeba7abd30f152977c605c6a3 c948b5da6bbec742b433138e3e3f9537a85af2e5 < 8d481f93588932a95f657671d4e1601b90d130cc c948b5da6bbec742b433138e3e3f9537a85af2e5 < e5e8fc11a7ac578f16079f855b7fffc1649d053c c948b5da6bbec742b433138e3e3f9537a85af2e5 < ef3e34874d2332d0f63e72c2c35ce5c93568c125
Linux / Linux
6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9a72b180f0575e41471e088e09bddc4b73d6dee2 git.kernel.org: https://git.kernel.org/stable/c/22edb6786127271aeba7abd30f152977c605c6a3 git.kernel.org: https://git.kernel.org/stable/c/8d481f93588932a95f657671d4e1601b90d130cc git.kernel.org: https://git.kernel.org/stable/c/e5e8fc11a7ac578f16079f855b7fffc1649d053c git.kernel.org: https://git.kernel.org/stable/c/ef3e34874d2332d0f63e72c2c35ce5c93568c125