SB20260812352 - NULL pointer dereference in Linux kernel mt76 mt7615 driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-68195)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in mt7615_rx_check() and mt7615_queue_rx_skb() when processing PKT_TYPE_TXRX_NOTIFY on non-mmio buses. A local user can trigger the RX worker to handle a crafted TXRX_NOTIFY event to cause a denial of service.
The issue affects mt7663 USB and SDIO buses where the tx_cleanup callback is NULL.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/39afc46c0243d10b7795e6e6cf4ae91f41732120
- https://git.kernel.org/stable/c/88c98ef247a3126fea9bbbda953a18a2f36c3ea7
- https://git.kernel.org/stable/c/ab4d213393e846baa6437497f94dda7553cbeda7
- https://git.kernel.org/stable/c/b2ab73b8123ce6cf2bc32634bfee4928676ffa66
- https://git.kernel.org/stable/c/f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5