CVE-2026-80825
Received Received - Intake

Buffer Overflow in Linux Kernel mt76 WiFi Driver

Vulnerability report for CVE-2026-80825, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there. That holds for locally generated traffic, where mac80211 reserves hw->extra_tx_headroom, but forwarded frames are sent through ieee80211_8023_xmit(), which does not reserve it. Bridge a wired interface to an mt7925u AP and the first forwarded frame that arrives short panics the kernel: skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1 kernel BUG at net/core/skbuff.c:212! Call trace: skb_panic+0x58/0x60 (P) skb_push+0x58/0x60 mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common] mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb] __mt76_tx_queue_skb+0x54/0xe8 [mt76] mt76_txq_schedule.part.0+0x204/0x478 [mt76] mt76_txq_schedule_all+0x50/0x80 [mt76] mt792x_tx_worker+0x68/0x100 [mt792x_lib] __mt76_worker_fn+0x84/0x150 [mt76] Whether a given setup hits it depends on how much headroom the ingress netdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging onboard ethernet to a Netgear A9000; originally reported on an MT7986 router running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet), which leaves more headroom, helped narrow the trigger to the ingress path. The same bug was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76: mt7921: don't assume adequate headroom for SDIO headers"), but mt7925 was copied from mt7921 without the fix. Add the same guard here.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mt76 mt7925 *
mt76 mt7921 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel affects the mt76 driver for MediaTek MT7925 Wi-Fi chips. It occurs when the driver assumes there is enough space at the start of network packets (headroom) to add a transmission descriptor and USB header. However, when packets are forwarded through a bridge, the headroom may not be reserved, causing a kernel panic when the driver tries to add data beyond the available space.

Detection Guidance

This vulnerability may cause a kernel panic when forwarding frames through an mt7925u AP. Check system logs for skbuff errors or kernel panics related to skb_push or mt7925_usb_sdio_tx_prepare_skb. Monitor for crashes after bridging a wired interface to an mt7925u AP.

Impact Analysis

If you use a system with an MT7925 Wi-Fi chip (e.g., Raspberry Pi 5 or Netgear A9000) and bridge a wired network interface to the Wi-Fi, the first forwarded packet could crash the kernel. This leads to a system reboot or denial of service, disrupting network connectivity and potentially causing data loss.

Mitigation Strategies

Apply the Linux kernel patch that adds headroom checks for forwarded frames in mt7925_usb_sdio_tx_prepare_skb. Avoid bridging wired interfaces to mt7925u APs until the fix is applied. Monitor vendor advisories for updates to mt76 drivers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80825. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart