CVE-2026-68307: wifi: mt76: mt7925: fix crash in reset link replay

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081031-CVE-2026-68307-54a5@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: fix crash in reset link replay

During reset recovery, mt7925_vif_connect_iter() replays firmware state
for links tracked in mvif->valid_links. After MLO link changes or MCU
timeout recovery, the driver bitmap can temporarily contain a link whose
mac80211 bss_conf has already gone away.

This can pass a NULL bss_conf to mt76_connac_mcu_uni_add_dev(), matching
the crash where x1, the second argument, is NULL:

pc : mt76_connac_mcu_uni_add_dev+0x8c/0x1f8 [mt76_connac_lib]
lr : mt7925_vif_connect_iter+0x9c/0x168 [mt7925_common]
x2 : ffffff80a77f6018 x1 : 0000000000000000 x0 : ffffff8099402080
Call trace:
mt76_connac_mcu_uni_add_dev+0x8c/0x1f8 [mt76_connac_lib]
mt7925_vif_connect_iter+0x9c/0x168 [mt7925_common]
mt7925_mac_reset_work+0x264/0x2f8 [mt7925_common]

Skip missing bss_conf entries before replaying the link. Non-MLO AP/STA
reset replay is unchanged because the helper still returns &vif->bss_conf
for the legacy link.

The Linux kernel CVE team has assigned CVE-2026-68307 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.11 with commit 14061994184df6bb89cba31657ee1db24480e92a and fixed in 6.12.101 with commit d9326796a378f80be5f9fd60983c62fdccdf2f0b
	Issue introduced in 6.11 with commit 14061994184df6bb89cba31657ee1db24480e92a and fixed in 6.18.42 with commit 95b0cf02731c74e073ef8937f5526bd4442a0326
	Issue introduced in 6.11 with commit 14061994184df6bb89cba31657ee1db24480e92a and fixed in 7.1.6 with commit 89d03bda560d635f66d495f37b46a187fd4edfdf
	Issue introduced in 6.11 with commit 14061994184df6bb89cba31657ee1db24480e92a and fixed in 7.2-rc5 with commit bd8b2ec838184236c3fcbf738a926328836adf12

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-68307
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/wireless/mediatek/mt76/mt7925/mac.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/d9326796a378f80be5f9fd60983c62fdccdf2f0b
	https://git.kernel.org/stable/c/95b0cf02731c74e073ef8937f5526bd4442a0326
	https://git.kernel.org/stable/c/89d03bda560d635f66d495f37b46a187fd4edfdf
	https://git.kernel.org/stable/c/bd8b2ec838184236c3fcbf738a926328836adf12
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.