Junglewise Threat Intelligence

CVE-2026-53098: Linux Kernel mt7915 Wi-Fi driver use-after-free in mt7915_mac_dump_work

CVE-2026-53098 · Severity: info · CVSS 5.5 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's MediaTek mt7915 Wi-Fi driver. When the Wi-Fi hardware is being removed or detached from the system, a race condition can occur that causes the system to attempt to use memory that has already been cleared. This can lead to system instability, crashes, or a denial of service.

Technical details

A use-after-free (UAF) vulnerability exists in the mt76 mt7915 driver within the mt7915_mac_dump_work() function. The issue is caused by a race condition between the PCI device removal path and the asynchronous workqueue. When the chip is detached, mt7915_coredump_unregister() releases the crash_data memory; however, if a dump_work item is still pending or executing, it may attempt to dereference this freed memory. The fix introduces cancel_work_sync() in the unregister path to ensure all pending work is completed or canceled before memory deallocation. This requires local access and typically occurs during hardware removal or driver unbinding.

Affected products

  • Linux Linux Kernel 6.2 to 6.6.140, 6.12.90, 6.18.32, 7.0.9

Timeline

  • 2026-01-30: patched: Initial patch submitted by Duoming Zhou
  • 2026-06-24: advisory: CVE-2026-53098 published

References

Related threats