Answer in brief
CVE-2026-89523 records a Unknown severity vulnerability in wifi: mt76: mt7925: cancel pending mlo_pm_work. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=276a568832577c81ec90b62dc506bbdc3781ca46 <5be6d02837d418bc6c805b5cab1b338de6de9ca7 || >=276a568832577c81ec90b62dc506bbdc3781ca46 <c5e073f2fbfd34d22099a50d96f60990799753e2 || >=276a568832577c81ec90b62dc506bbdc3781ca46 <2889e84282dda147f10b10d94cf0efd90a349c53 || 74eb79258bfd5f2ffe6d26a09c898992b2afa1ce || >=6.14.3 <6.15 | 5be6d02837d418bc6c805b5cab1b338de6de9ca7, c5e073f2fbfd34d22099a50d96f60990799753e2, 2889e84282dda147f10b10d94cf0efd90a349c53, 6.15 |
| Linux/Linuxgeneric | 6.15 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel pending mlo_pm_work If the device is reset, suspended or unregistered within that window, the pending work can still run and access vif/bss data that may already be freed, or send MCU commands while the firmware is not available. Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown and suspend paths: - mt7925_mac_reset_work() (chip reset recovery) - mt7925e_unregister_device() (PCIe unbind) - mt7925_pci_suspend() (PCIe bus suspend) - mt7925_suspend() (mac80211 suspend) - mt7925u_suspend() (USB bus / runtime suspend) This ensures the work is stopped before the device state becomes invalid.
Quoted source text, attributed separately from HOL analysis.