In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: use kfreercu for offchannel link in mt76putvifphy_link
mt76putvifphylink() frees the offchannel mlink with plain kfree() after rcuassignpointer(NULL). However, rcuassignpointer only prevents future RCU readers from obtaining the pointer -- it does not wait for existing readers that already hold it via rcu_dereference.
The TX datapath (e.g. mt7996macwritetxwi) dereferences mlink->wcid and mlink->idx under rcureadlock. If a TX softirq obtained the pointer via rcudereference just before the NULL assignment, it will dereference freed memory after the kfree.
struct mt76viflink already contains an rcuhead field that is unused at this free site -- a developer oversight, since the adjacent kfreercumightsleep call for rxsc in the same function shows the pattern was understood.
Replace kfree(mlink) with kfreercu(mlink, rcuhead).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74325.json",
"cna_assigner": "Linux"
}