GHSA-4c4x-fg8c-5526unknown
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: clear...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
mt7915_remove_interface() cleared the wcid mask bit with no lock held and before clearing the RCU wcid pointer. The mask is a non-atomic RMW shared with the allocators, which all run under dev->mt76.mutex; on DBDC the two wiphys share one mt76_dev, so this raced add_interface/sta_add on the other band and could leak or double-hand-out a wcid. Clearing the bit before the RCU pointer also let a concurrent allocation reuse the index and publish its wcid, which the subsequent NULL assignment then wiped. Move the clear into the existing mutex section, after the RCU pointer is cleared.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90373
- https://git.kernel.org/stable/c/5dce25f1d609ba991a9c22c27be586c92f03ed77
- https://git.kernel.org/stable/c/6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba
- https://git.kernel.org/stable/c/a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b
- https://git.kernel.org/stable/c/b4a41a47a67c788e6b0625fa517ec8872e99bb6c
- https://github.com/advisories/GHSA-4c4x-fg8c-5526