Executive brief
The mt76 WiFi driver in the Linux kernel contains a memory safety bug in the function that cleans up virtual interface links. When a WiFi interface link is torn down, the code frees memory immediately without waiting for in-flight network transmissions that may still be accessing it. This can cause a kernel crash or allow an attacker with local network access to trigger a denial of service.
Technical details
The vulnerability is a use-after-free in the mt76 WiFi driver's mt76_put_vif_phy_link() function. The function uses plain kfree() to free the offchannel memory link (mlink) after calling rcu_assign_pointer(NULL), but RCU read-side critical sections in the TX datapath (e.g., mt7996_mac_write_txwi) may still hold references acquired via rcu_dereference. The rcu_assign_pointer() call only prevents future readers from obtaining the pointer; it does not wait for existing readers. If a TX softirq obtains the pointer before the NULL assignment completes and the memory is freed, the softirq will subsequently dereference freed memory when accessing mlink->wcid or mlink->idx. The fix replaces the unsafe kfree(mlink) with kfree_rcu(mlink, rcu_head), which defers freeing until all RCU readers have exited. The struct mt76_vif_link already contained an unused rcu_head field, indicating this was a developer oversight.
Affected products
- Linux Linux kernel affected versions include Linux 6.x and later (introduced by commit a8f424c1287c)
Timeline
- 2026-08-15: disclosed
- 2026-06-09: patched: upstream fix committed
- 2026-07-24: patched: backported to stable