From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4CA964CC267 for ; Fri, 4 Sep 2026 15:55:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537310; cv=none; b=GH7k/gyeaFK2RdypA5W3XVgKSPA5CvLYT17T2dKciJxxmuEttAAwVPMDFakeA0V03SRe5i/3BZRmkg5lpYZ2Xi8lnmCYW3Lkgb50xxU+dzenrVj5CT5e2M4DUcNfJrZPfAzd3IUwCmJH1tOgdIPgYk6FgvpQJFv/av9gnSC4Myw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537310; c=relaxed/simple; bh=ACwWUM5mhWyiX2dbLVlAbbZbA6Dhielx4khv4B/noBE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=hVMhWrADYCD6cPbWrEjCzRGJVLTm3CIR0H6VNi7DQgLJlIWYkZSrSBj7d+rxRJj7yux60bf6DlxD3Stxg2nLjsBJ5GsMWxg3Q2D8j7n13DvPf1vVgM56XJGLRHUmMmTRE91qqEQIyQY4xSLXHaLsM2is+ZFgE2bl9R1P8c+mVpQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=JtMvpSIK; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="JtMvpSIK" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 091611F00A3D; Fri, 4 Sep 2026 15:55:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788537307; bh=QFg9jeO+jeKtm4fRm/jjI+KxLxQ5jxFASAKuq+Ovhz8=; h=From:To:Cc:Subject:Date:Reply-To; b=JtMvpSIKtMuTSPW/jjORkIoPeFT/ae+AFh2B28hvdkUP6Dh3/KGda5fFa3FIHhRau w7QMKVdpDyv3+WvCKlhY1Ar2lHXhynZ07L+k8qDhofioSn3WnuiQjXFDwhYHKNnUhq fTWSl/DTPWuIKccmtXuzAOFIkT0uVTNdSskhMZjk= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80825: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb Date: Fri, 4 Sep 2026 17:52:52 +0200 Message-ID: <2026090454-CVE-2026-80825-3632@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3970; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=uL6FY+WXQ9MEQhWHUvxZydfpHd1ypEpzIUAkx4FK/5o=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzXobNV766n1/uu6WIq8uT3q7y/ROkFzvpfHMMtovo+ 2cwLXteRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEyk7DbDPJ2JFdfblif9V4jJ 6or3Pe34T+nkW4YFE89YfAoosSpNFngi87Ug/ZHs1hfKAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there. That holds for locally generated traffic, where mac80211 reserves hw->extra_tx_headroom, but forwarded frames are sent through ieee80211_8023_xmit(), which does not reserve it. Bridge a wired interface to an mt7925u AP and the first forwarded frame that arrives short panics the kernel: skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1 kernel BUG at net/core/skbuff.c:212! Call trace: skb_panic+0x58/0x60 (P) skb_push+0x58/0x60 mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common] mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb] __mt76_tx_queue_skb+0x54/0xe8 [mt76] mt76_txq_schedule.part.0+0x204/0x478 [mt76] mt76_txq_schedule_all+0x50/0x80 [mt76] mt792x_tx_worker+0x68/0x100 [mt792x_lib] __mt76_worker_fn+0x84/0x150 [mt76] Whether a given setup hits it depends on how much headroom the ingress netdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging onboard ethernet to a Netgear A9000; originally reported on an MT7986 router running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet), which leaves more headroom, helped narrow the trigger to the ingress path. The same bug was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76: mt7921: don't assume adequate headroom for SDIO headers"), but mt7925 was copied from mt7921 without the fix. Add the same guard here. The Linux kernel CVE team has assigned CVE-2026-80825 to this issue. Affected and fixed versions =========================== Issue introduced in 6.7 with commit c948b5da6bbec742b433138e3e3f9537a85af2e5 and fixed in 6.12.108 with commit 9a72b180f0575e41471e088e09bddc4b73d6dee2 Issue introduced in 6.7 with commit c948b5da6bbec742b433138e3e3f9537a85af2e5 and fixed in 6.18.49 with commit 22edb6786127271aeba7abd30f152977c605c6a3 Issue introduced in 6.7 with commit c948b5da6bbec742b433138e3e3f9537a85af2e5 and fixed in 7.1.13 with commit 8d481f93588932a95f657671d4e1601b90d130cc Issue introduced in 6.7 with commit c948b5da6bbec742b433138e3e3f9537a85af2e5 and fixed in 7.2.3 with commit e5e8fc11a7ac578f16079f855b7fffc1649d053c Issue introduced in 6.7 with commit c948b5da6bbec742b433138e3e3f9537a85af2e5 and fixed in 7.3-rc1 with commit ef3e34874d2332d0f63e72c2c35ce5c93568c125 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80825 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/wireless/mediatek/mt76/mt7925/mac.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9a72b180f0575e41471e088e09bddc4b73d6dee2 https://git.kernel.org/stable/c/22edb6786127271aeba7abd30f152977c605c6a3 https://git.kernel.org/stable/c/8d481f93588932a95f657671d4e1601b90d130cc https://git.kernel.org/stable/c/e5e8fc11a7ac578f16079f855b7fffc1649d053c https://git.kernel.org/stable/c/ef3e34874d2332d0f63e72c2c35ce5c93568c125