---
id: CVE-2026-64325
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon

  This patch is based on a BUG as reported by Bongani Hlope at
  https://lore.kernel.org/all/20260502125824.4…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon

  This patch is based on a BUG as reported by Bongani Hlope at
  https://lore.kernel.org/all/20260502125824.4…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.14, < 7.1.4'
patched:
  - linux_kernel 7.1.4
published: '2026-07-25'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64325'
references:
  - url: 'https://git.kernel.org/stable/c/351dd7d2c80d23e56dcce6faa4e62bea5b0877c7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/77e7b127472a191e086e1e0b1b051703f33b1801'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00141
epssPercentile: 0.02811
ingestedAt: '2026-09-05T13:39:56.154Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon

This patch is based on a BUG as reported by Bongani Hlope at
https://lore.kernel.org/all/20260502125824.425d7159@bongani-mini.home.org.za/

When a channel-switch announcement (CSA) beacon is received,
cfg80211 queues a wiphy work item that eventually calls
mt7921_channel_switch_rx_beacon(). If the station disconnects
(or the channel context is otherwise torn down) between the
time the work is queued and the time it runs, the driver's
dev->new_ctx pointer can already have been cleared to NULL.
mt7921_channel_switch_rx_beacon() then dereferences new_ctx
unconditionally, triggering a NULL pointer dereference at
address 0x0:

  BUG: kernel NULL pointer dereference, address: 0000000000000000
  RIP: 0010:mt7921_channel_switch_rx_beacon+0x1f/0x100 [mt7921_common]

The same missing guard exists in mt7925_channel_switch_rx_beacon(),
which shares the same code pattern introduced by the same commit.

Add an early-return NULL check for dev->new_ctx in both
mt7921_channel_switch_rx_beacon() and
mt7925_channel_switch_rx_beacon(). When new_ctx is NULL there is
no pending channel switch to process, so returning immediately is
the correct and safe action.

Oops-Analysis: http://oops.fenrus.org/reports/lkml/20260502125824.425d7159@bongani-mini.home.org.za/report.html

## Affected

- `linux_kernel >= 6.14, < 7.1.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.1.4`
