Executive brief
A vulnerability was identified in the Linux kernel's MediaTek mt7915 Wi-Fi driver. When the Wi-Fi hardware is being removed or detached from the system, a race condition can occur that causes the system to attempt to use memory that has already been cleared. This can lead to system instability, crashes, or a denial of service.
Technical details
A use-after-free (UAF) vulnerability exists in the mt76 mt7915 driver within the mt7915_mac_dump_work() function. The issue is caused by a race condition between the PCI device removal path and the asynchronous workqueue. When the chip is detached, mt7915_coredump_unregister() releases the crash_data memory; however, if a dump_work item is still pending or executing, it may attempt to dereference this freed memory. The fix introduces cancel_work_sync() in the unregister path to ensure all pending work is completed or canceled before memory deallocation. This requires local access and typically occurs during hardware removal or driver unbinding.
Affected products
- Linux Linux Kernel 6.2 to 6.6.140, 6.12.90, 6.18.32, 7.0.9
Timeline
- 2026-01-30: patched: Initial patch submitted by Duoming Zhou
- 2026-06-24: advisory: CVE-2026-53098 published
References
- https://git.kernel.org/stable/c/1146d0946b5358fad24812bd39d68f31cd40cc34
- https://git.kernel.org/stable/c/21ce6d867867645fff0ef657be18f61d9f39dcd8
- https://git.kernel.org/stable/c/6b7cbb13c838cf2a5f2e7be0e96fe15250087939
- https://git.kernel.org/stable/c/6d5202409467d621b6d1dfd7fc7dadb997fe66d2
- https://git.kernel.org/stable/c/e6856af8a22a8e2cd18241a465ed00c2301b3a5e