CVE-2026-68195

Source
https://cve.org/CVERecord?id=CVE-2026-68195
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68195.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68195
Downstream
Published
2026-08-10T12:00:13Z
Modified
2026-08-21T03:30:31Z
Summary
wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses

PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus. mt7615_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the mmio queue ops implement that callback; on the mt7663 USB and SDIO buses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker. Same defect as the mt7921 and mt7925 patches in this series.

Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for non-mmio devices").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68195.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eb99cc95c3b6513b495c4839ac4917206705f657
Fixed
664f8bbc61e45e062679da512bf12f8f6fb26a1b
Fixed
1a099d630b8667fa622662b85e35a0ef659fb343
Fixed
a0b3e8d8726c3830102a18946c766c94c953c7f2
Fixed
f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5
Fixed
88c98ef247a3126fea9bbbda953a18a2f36c3ea7
Fixed
ab4d213393e846baa6437497f94dda7553cbeda7
Fixed
b2ab73b8123ce6cf2bc32634bfee4928676ffa66
Fixed
39afc46c0243d10b7795e6e6cf4ae91f41732120

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68195.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68195.json"