CVE-2026-74325: wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: use kfreercu for offchannel link in mt76putvifphylink
mt76putvifphylink() frees the offchannel mlink with plain kfree() after rcuassignpointer(NULL). However, rcuassignpointer only prevents future RCU readers from obtaining the pointer -- it does not wait for existing readers that already hold it via rcudereference.
The TX datapath (e.g. mt7996macwritetxwi) dereferences mlink->wcid and mlink->idx under rcureadlock. If a TX softirq obtained the pointer via rcudereference just before the NULL assignment, it will dereference freed memory after the kfree.
struct mt76viflink already contains an rcuhead field that is unused at this free site -- a developer oversight, since the adjacent kfreercumightsleep call for rxsc in the same function shows the pattern was understood.
Replace kfree(mlink) with kfreercu(mlink, rcuhead).