CVE-2026-68195

Source
https://cve.org/CVERecord?id=CVE-2026-68195
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68195.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68195
Downstream
Published
2026-08-10T12:00:13.627Z
Modified
2026-08-12T04:18:46.568289262Z
Summary
wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses

PKTTYPETXRXNOTIFY is an mmio-only event, but mt7615rxcheck() and mt7615queuerxskb() dispatch it to mt7615mactxfree() on every bus. mt7615mactxfree() cleans the DMA tx queues with mt76queuetxcleanup(), which calls queueops->txcleanup(). Only the mmio queue ops implement that callback; on the mt7663 USB and SDIO buses it is NULL, so a TXRXNOTIFY there calls a NULL pointer in the RX worker. Same defect as the mt7921 and mt7925 patches in this series.

Drop the event on non-mmio buses via mt76ismmio(), as in commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for non-mmio devices").

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68195.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eb99cc95c3b6513b495c4839ac4917206705f657
Fixed
f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5
Fixed
88c98ef247a3126fea9bbbda953a18a2f36c3ea7
Fixed
ab4d213393e846baa6437497f94dda7553cbeda7
Fixed
b2ab73b8123ce6cf2bc32634bfee4928676ffa66
Fixed
39afc46c0243d10b7795e6e6cf4ae91f41732120

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68195.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68195.json"