Answer in brief
CVE-2026-68194 records a Unknown severity vulnerability in wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=48fab5bbef4092d925ab3214773ad12e68807223 <ef2ee5f820c3ef87643b51e960c20b4a14d8336b || >=48fab5bbef4092d925ab3214773ad12e68807223 <ecf995b828191829ba4a87169bccabcbeb5c9c32 || >=48fab5bbef4092d925ab3214773ad12e68807223 <263816e92e8d66c81c98ccab2b5d2191ed08ec71 || >=48fab5bbef4092d925ab3214773ad12e68807223 <24475d2ddc8d8dfd82f4d2be0d951401f86911a6 || >=48fab5bbef4092d925ab3214773ad12e68807223 <da4082e91acabc1498611ed8ccc53f0610baefc6 | ef2ee5f820c3ef87643b51e960c20b4a14d8336b, ecf995b828191829ba4a87169bccabcbeb5c9c32, 263816e92e8d66c81c98ccab2b5d2191ed08ec71, 24475d2ddc8d8dfd82f4d2be0d951401f86911a6, da4082e91acabc1498611ed8ccc53f0610baefc6 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus. mt7921_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the mmio queue ops implement that callback; on USB and SDIO it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker: BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:0x0 Call Trace: mt7921_mac_tx_free+0x64/0x310 [mt7921_common] mt7921_rx_check+0x5f/0xf0 [mt7921_common] mt76u_rx_worker+0x1b9/0x620 [mt76_usb] Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for non-mmio devices").
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68194 records a Unknown severity vulnerability in wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=48fab5bbef4092d925ab3214773ad12e68807223 <ef2ee5f820c3ef87643b51e960c20b4a14d8336b || >=48fab5bbef4092d925ab3214773ad12e68807223 <ecf995b828191829ba4a87169bccabcbeb5c9c32 || >=48fab5bbef4092d925ab3214773ad12e68807223 <263816e92e8d66c81c98ccab2b5d2191ed08ec71 || >=48fab5bbef4092d925ab3214773ad12e68807223 <24475d2ddc8d8dfd82f4d2be0d951401f86911a6 || >=48fab5bbef4092d925ab3214773ad12e68807223 <da4082e91acabc1498611ed8ccc53f0610baefc6 | ef2ee5f820c3ef87643b51e960c20b4a14d8336b, ecf995b828191829ba4a87169bccabcbeb5c9c32, 263816e92e8d66c81c98ccab2b5d2191ed08ec71, 24475d2ddc8d8dfd82f4d2be0d951401f86911a6, da4082e91acabc1498611ed8ccc53f0610baefc6 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus. mt7921_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the mmio queue ops implement that callback; on USB and SDIO it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker: BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:0x0 Call Trace: mt7921_mac_tx_free+0x64/0x310 [mt7921_common] mt7921_rx_check+0x5f/0xf0 [mt7921_common] mt76u_rx_worker+0x1b9/0x620 [mt76_usb] Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for non-mmio devices").
Quoted source text, attributed separately from HOL analysis.