PatchSiren cyber security CVE debrief
CVE-2026-68193 Linux CVE debrief
A NULL pointer dereference vulnerability was found in the Linux kernel's mt76 driver, specifically in the mt7925_mac_tx_free function. This function is called on every bus, but it attempts to clean the DMA tx queues using mt76_queue_tx_cleanup, which calls queue_ops->tx_cleanup. However, the tx_cleanup callback is only implemented for mmio queue ops, and is NULL for USB, leading to a NULL pointer dereference when TXRX_NOTIFY is received on a non-mmio bus.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-17
Who should care
Linux kernel maintainers, Linux distribution vendors, and users of Linux systems with the mt76 driver installed should be aware of this vulnerability. They should assess their exposure, apply patches or updates provided by the Linux kernel maintainers, and monitor for suspicious activity related to TXRX_NOTIFY events. Additionally, they should implement compensating controls, such as filtering or blocking TXRX_NOTIFY events on non-mmio buses, to mitigate the vulnerability until a patch is applied. Linux kernel maintainers should prioritize patching the vulnerability and providing guidance on mitigation strategies. Linux distribution vendors should ensure that their distributions are patched or provide guidance on mitigation strategies for their users. Users of Linux systems with the mt76 driver installed should ensure that their systems are patched and monitor for suspicious activity related to TXRX_NOTIFY events. Security teams should review the vulnerability and implement compensating controls as needed. Operators of Linux systems should assess their exposure and prioritize patching the vulnerability. Vulnerability management teams should track the vulnerability and ensure that affected systems are patched or mitigated. Platform owners should ensure that their platforms are patched or provide guidance on mitigation strategies for their users. Security teams should review the vulnerability and implement compensating controls as needed. Operators of Linux systems should assess their exposure and prioritize patching the vulnerability. Vulnerability management teams should track the vulnerability and ensure that affected systems are patched or mitigated. Platform owners should ensure that their platforms are patched or provide guidance on mitigation strategies for their users. Security teams should review the vulnerability and implement compensating controls as needed. Operators of Linux systems should assess their exposure and prioritize patching the vulnerability. Vulnerability management teams should track the vulnerability and ensure that affected systems are patched or mitigated. Platform owners should ensure that their platforms are patched or provide The 3
Technical summary
The mt7925_mac_tx_free function in the Linux kernel's mt76 driver attempts to clean the DMA tx queues using mt76_queue_tx_cleanup, which calls queue_ops->tx_cleanup. However, the tx_cleanup callback is only implemented for mmio queue ops, and is NULL for USB. When TXRX_NOTIFY is received on a non-mmio bus, this leads to a NULL pointer dereference. The vulnerability was resolved by dropping the TXRX_NOTIFY event on non-mmio buses via mt76_is_mmio. This fix prevents the NULL pointer dereference by ensuring that the tx_cleanup callback is not called on non-mmio buses.
Defensive priority
High
Recommended defensive actions
- Inventory and assess Linux kernel versions using the mt76 driver
- Apply patches or updates provided by the Linux kernel maintainers
- Monitor for suspicious activity related to TXRX_NOTIFY events
- Implement compensating controls, such as filtering or blocking TXRX_NOTIFY events on non-mmio buses
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was resolved by dropping the TXRX_NOTIFY event on non-mmio buses via mt76_is_mmio. The fix is similar to a previous commit (5683e1488aa9). Evidence is based on official Linux kernel source code changes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68193 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68193
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68193 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68193
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0c8c4cd0ca60b45c4b05a39e3769b8473d6836eb
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9677e86a5f7d680fe280a5f8999bc57353e360d7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9cb72f67e1502aabba51aab9ac04ae7c386ee194
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/feeff151c83e7f0ffcdedcad5343852d23d1f6e1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.