Bug 2532443 (CVE-2026-80938) - CVE-2026-80938 kernel: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
Summary: CVE-2026-80938 kernel: wifi: mt76: mt7615: avoid waiting for mac work under t...
Keywords:
Status: NEW
Alias: CVE-2026-80938
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 23:17 UTC by OSIDB Bzimport
Modified: 2026-09-14 14:37 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-11 23:17:57 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex

mt7615_suspend() acquired the mt76 mutex and then called
cancel_delayed_work_sync() on mac_work.  mt7615_mac_work() acquires the
same mutex via mt7615_mutex_acquire() at the top of the worker, so if
mac_work is already running and blocked on the mutex, the suspend path
deadlocks waiting for the work it holds the mutex against.

Flush scan_work and mac_work before taking the mutex, matching the
suspend paths in mt7921 and mt7925.  scan_work only takes the mt76
spinlock, but moving it keeps the sequence consistent.  This also keeps
mac_work from running over an already suspended HIF, which the previous
split (async cancel under the lock, sync cancel after release) would
have allowed.


Note You need to log in before you can comment on or make changes to this bug.