Executive brief
A vulnerability in the Linux kernel's MediaTek Wi-Fi driver could cause a system deadlock, leading to a complete loss of wireless connectivity or a system hang. This occurs specifically when removing a Wi-Fi station or during certain power management transitions. While it does not directly expose data, it impacts the reliability and availability of devices using affected MediaTek wireless hardware.
Technical details
A potential deadlock exists in the mt7921 driver within the mt7921_roc_abort_sync function. The issue arises because roc_abort_sync() calls cancel_work_sync() while potentially holding the dev->mt76.mutex. Simultaneously, the roc_work() thread may be running and attempting to acquire the same mutex, or already holding it while cancel_work_sync() waits for it to complete. This circular dependency occurs during station removal paths (mt76_sta_remove). The fix involves using test_and_clear_bit to manage state and replacing the synchronous cancel_work_sync() with an asynchronous cancel_work() to break the wait-cycle. Patches have been released for various stable kernel branches including 6.18.x and 7.0.x.
Affected products
- Linux Linux Kernel 6.9 to 7.1
Timeline
- 2026-01-26: disclosed: Initial patch submitted by MediaTek developers
- 2026-06-24: advisory: CVE-2026-53101 published