NULL pointer dereference in Linux kernel - CVE-2026-64325
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon() when processing a channel-switch announcement beacon after the channel context has been torn down. A remote attacker can send a channel-switch announcement beacon to trigger a kernel crash and cause a denial of service.
Exploitation requires a race condition where the queued work executes after the station disconnects or the channel context is otherwise removed.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64325
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13