Answer in brief
CVE-2026-53098 records a Unknown severity vulnerability in wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4bf3f4755611e3ae4cca58469e3c1d73be9c8093 <55159f1fa30bef03e01af469823c1de103a4a884 || >=4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 <6d5202409467d621b6d1dfd7fc7dadb997fe66d2 || >=4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 <e6856af8a22a8e2cd18241a465ed00c2301b3a5e || >=4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 <6b7cbb13c838cf2a5f2e7be0e96fe15250087939 || >=4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 <21ce6d867867645fff0ef657be18f61d9f39dcd8 || >=4dbcb9125cc3e10a6d879c10e4f5816d05a87c49 <1146d0946b5358fad24812bd39d68f31cd40cc34 | 55159f1fa30bef03e01af469823c1de103a4a884, 6d5202409467d621b6d1dfd7fc7dadb997fe66d2, e6856af8a22a8e2cd18241a465ed00c2301b3a5e, 6b7cbb13c838cf2a5f2e7be0e96fe15250087939, 21ce6d867867645fff0ef657be18f61d9f39dcd8, 1146d0946b5358fad24812bd39d68f31cd40cc34 |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() When the mt7915 pci chip is detaching, the mt7915_crash_data is released in mt7915_coredump_unregister(). However, the work item dump_work may still be running or pending, leading to UAF bugs when the already freed crash_data is dereferenced again in mt7915_mac_dump_work(). The race condition can occur as follows: CPU 0 (removal path) | CPU 1 (workqueue) mt7915_pci_remove() | mt7915_sys_recovery_set() mt7915_unregister_device() | mt7915_reset() mt7915_coredump_unregister() | queue_work() vfree(dev->coredump.crash_data) | mt7915_mac_dump_work() | crash_data-> // UAF Fix this by ensuring dump_work is properly canceled before the crash_data is deallocated. Add cancel_work_sync() in mt7915_unregister_device() to synchronize with any pending or executing dump work.
Quoted source text, attributed separately from HOL analysis.