{"id":"CVE-2026-53098","title":"wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()\n\nWhen the mt7915 pci chip is detaching, the mt7915_crash_data is\nreleased in mt7915_coredump_unreg…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 4bf3f4755611e3ae4cca58469e3c1d73be9c8093 < 55159f1fa30bef03e01af469823c1de103a4a884","Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 6d5202409467d621b6d1dfd7fc7dadb997fe66d2","Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < e6856af8a22a8e2cd18241a465ed00c2301b3a5e","Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 6b7cbb13c838cf2a5f2e7be0e96fe15250087939","Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 21ce6d867867645fff0ef657be18f61d9f39dcd8","Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 1146d0946b5358fad24812bd39d68f31cd40cc34","Linux 6.2"],"published":"2026-06-24","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:31.148Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-53098","references":[{"url":"https://git.kernel.org/stable/c/55159f1fa30bef03e01af469823c1de103a4a884"},{"url":"https://git.kernel.org/stable/c/6d5202409467d621b6d1dfd7fc7dadb997fe66d2"},{"url":"https://git.kernel.org/stable/c/e6856af8a22a8e2cd18241a465ed00c2301b3a5e"},{"url":"https://git.kernel.org/stable/c/6b7cbb13c838cf2a5f2e7be0e96fe15250087939"},{"url":"https://git.kernel.org/stable/c/21ce6d867867645fff0ef657be18f61d9f39dcd8"},{"url":"https://git.kernel.org/stable/c/1146d0946b5358fad24812bd39d68f31cd40cc34"}],"tags":["cve.org"],"epss":0.00171,"epssPercentile":0.0574,"ingestedAt":"2026-09-14T15:23:07.457Z","slug":"CVE-2026-53098","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()\n\nWhen the mt7915 pci chip is detaching, the mt7915_crash_data is\nreleased in mt7915_coredump_unregister(). However, the work item\ndump_work may still be running or pending, leading to UAF bugs\nwhen the already freed crash_data is dereferenced again in\nmt7915_mac_dump_work().\n\nThe race condition can occur as follows:\n\nCPU 0 (removal path)               | CPU 1 (workqueue)\nmt7915_pci_remove()                | mt7915_sys_recovery_set()\n mt7915_unregister_device()        |  mt7915_reset()\n  mt7915_coredump_unregister()     |   queue_work()\n   vfree(dev->coredump.crash_data) | mt7915_mac_dump_work()\n                                   |  crash_data-> // UAF\n\nFix this by ensuring dump_work is properly canceled before\nthe crash_data is deallocated. Add cancel_work_sync() in\nmt7915_unregister_device() to synchronize with any pending\nor executing dump work.\n\n## Affected\n\n- `Linux >= 4bf3f4755611e3ae4cca58469e3c1d73be9c8093 < 55159f1fa30bef03e01af469823c1de103a4a884`\n- `Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 6d5202409467d621b6d1dfd7fc7dadb997fe66d2`\n- `Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < e6856af8a22a8e2cd18241a465ed00c2301b3a5e`\n- `Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 6b7cbb13c838cf2a5f2e7be0e96fe15250087939`\n- `Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 21ce6d867867645fff0ef657be18f61d9f39dcd8`\n- `Linux >= 4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 < 1146d0946b5358fad24812bd39d68f31cd40cc34`\n- `Linux 6.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}