Bug 2513471 (CVE-2026-68311) - CVE-2026-68311 kernel: wifi: mt76: mt7925: guard link STA in decap offload
Summary: CVE-2026-68311 kernel: wifi: mt76: mt7925: guard link STA in decap offload
Keywords:
Status: NEW
Alias: CVE-2026-68311
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 12:39 UTC by OSIDB Bzimport
Modified: 2026-08-11 09:19 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-10 12:39:14 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: guard link STA in decap offload

mt7925_sta_set_decap_offload() iterates over the vif valid_links mask
when updating decap offload state for an MLO station. The station may not
have a link STA for every valid link of the vif, so mt792x_sta_to_link()
can return NULL for a link that belongs to the vif but not to the station.

The function currently dereferences mlink before checking whether the
link WCID is ready. If mlink is NULL, setting or clearing
MT_WCID_FLAG_HDR_TRANS dereferences a NULL pointer.

Skip links without a station link before touching mlink->wcid.

Comment 1 Mauro Matteo Cascella 2026-08-11 09:17:16 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026081031-CVE-2026-68311-e53f@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.