CVE-2026-64325: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
This patch is based on a BUG as reported by Bongani Hlope at https://lore.kernel.org/all/20260502125824.425d7159@bongani-mini.home.org.za/
When a channel-switch announcement (CSA) beacon is received, cfg80211 queues a wiphy work item that eventually calls mt7921channelswitchrxbeacon(). If the station disconnects (or the channel context is otherwise torn down) between the time the work is queued and the time it runs, the driver's dev->newctx pointer can already have been cleared to NULL. mt7921channelswitchrxbeacon() then dereferences newctx unconditionally, triggering a NULL pointer dereference at address 0x0:
BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:mt7921channelswitchrxbeacon+0x1f/0x100 [mt7921common]
The same missing guard exists in mt7925channelswitchrxbeacon(), which shares the same code pattern introduced by the same commit.
Add an early-return NULL check for dev->newctx in both mt7921channelswitchrxbeacon() and mt7925channelswitchrxbeacon(). When newctx is NULL there is no pending channel switch to process, so returning immediately is the correct and safe action.
Oops-Analysis: http://oops.fenrus.org/reports/lkml/20260502125824.425d7159@bongani-mini.home.org.za/report.html
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In both mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon(), add an early-return NULL check for dev->new_ctx before any dereference; if no pending channel switch is present, return immediately to avoid NULL pointer dereference.
Linux kernel (mt76 mt7921/mt7925) Add early-return NULL guard for dev->new_ctx in mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon() = if (dev->new_ctx == NULL) return;
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux mt76 Wi-Fi driver for mt7921 or mt7925 hardware are exposed when processing channel-switch announcement beacons. The vulnerable paths are mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon().
What conditions are required to trigger the crash?
A CSA beacon must cause cfg80211 to queue wiphy work, and the station must disconnect or its channel context must be torn down before that work executes. In that race, dev->new_ctx is cleared and then dereferenced by the driver.
What is the likely impact?
The documented result is a kernel NULL pointer dereference at address 0x0, which can cause a denial of service through a kernel crash. The supplied CVSS vector indicates local access and low privileges are required, with no user interaction.
What does the fix do?
The fix adds an early return when dev->new_ctx is NULL in both affected channel-switch beacon handlers. This avoids dereferencing a cleared channel-context pointer when no channel switch is pending.