CVE-2026-80938

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex

mt7615_suspend() acquired the mt76 mutex and then called cancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the same mutex via mt7615_mutex_acquire() at the top of the worker, so if mac_work is already running and blocked on the mutex, the suspend path deadlocks waiting for the work it holds the mutex against.

Flush scan_work and mac_work before taking the mutex, matching the suspend paths in mt7921 and mt7925. scan_work only takes the mt76 spinlock, but moving it keeps the sequence consistent. This also keeps mac_work from running over an already suspended HIF, which the previous split (async cancel under the lock, sync cancel after release) would have allowed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc6bf20109a3fae92402cb76ad709ec5256bcd169 < 3114d479f2a1d31b2e6214c395794c6e5715e579affected
LinuxLinuxc6bf20109a3fae92402cb76ad709ec5256bcd169 < 4506e229b2e468b8c64bcf52c50c41a3bf2e633eaffected
LinuxLinuxc6bf20109a3fae92402cb76ad709ec5256bcd169 < 44be85af3e1772ffb3332feafedad2a73b22854caffected
LinuxLinuxc6bf20109a3fae92402cb76ad709ec5256bcd169 < bda8324270b1ac91bfba1df8928e0570e29759e8affected
LinuxLinux5.8affected
LinuxLinux0 < 5.8unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References