CVE-2026-64325: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon

Published Jul 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon

This patch is based on a BUG as reported by Bongani Hlope at https://lore.kernel.org/all/20260502125824.425d7159@bongani-mini.home.org.za/

When a channel-switch announcement (CSA) beacon is received, cfg80211 queues a wiphy work item that eventually calls mt7921channelswitchrxbeacon(). If the station disconnects (or the channel context is otherwise torn down) between the time the work is queued and the time it runs, the driver's dev->newctx pointer can already have been cleared to NULL. mt7921channelswitchrxbeacon() then dereferences newctx unconditionally, triggering a NULL pointer dereference at address 0x0:

BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:mt7921channelswitchrxbeacon+0x1f/0x100 [mt7921common]

The same missing guard exists in mt7925channelswitchrxbeacon(), which shares the same code pattern introduced by the same commit.

Add an early-return NULL check for dev->newctx in both mt7921channelswitchrxbeacon() and mt7925channelswitchrxbeacon(). When newctx is NULL there is no pending channel switch to process, so returning immediately is the correct and safe action.

Oops-Analysis: http://oops.fenrus.org/reports/lkml/20260502125824.425d7159@bongani-mini.home.org.za/report.html

Affected Software

2 affected components
Linux Kernel
Linux Linux kernel>=6.14<7.1.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In both mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon(), add an early-return NULL check for dev->new_ctx before any dereference; if no pending channel switch is present, return immediately to avoid NULL pointer dereference.

    Linux kernel (mt76 mt7921/mt7925) Add early-return NULL guard for dev->new_ctx in mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon() = if (dev->new_ctx == NULL) return;

Event History

Jul 25, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
Description
Data Sourced
via NVD·10:17 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux mt76 Wi-Fi driver for mt7921 or mt7925 hardware are exposed when processing channel-switch announcement beacons. The vulnerable paths are mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon().

2

What conditions are required to trigger the crash?

A CSA beacon must cause cfg80211 to queue wiphy work, and the station must disconnect or its channel context must be torn down before that work executes. In that race, dev->new_ctx is cleared and then dereferenced by the driver.

3

What is the likely impact?

The documented result is a kernel NULL pointer dereference at address 0x0, which can cause a denial of service through a kernel crash. The supplied CVSS vector indicates local access and low privileges are required, with no user interaction.

4

What does the fix do?

The fix adds an early return when dev->new_ctx is NULL in both affected channel-switch beacon handlers. This avoids dereferencing a cleared channel-context pointer when no channel switch is pending.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203