HomeDefectsLIN1024-30948
Fixed

LIN1024-30948 : Security Advisory - linux - CVE-2026-89523

Created: Oct 6, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.24.33.2
Fix Version: 10.24.33.5
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7925: cancel pending mlo_pm_work  If the device is reset, suspended or unregistered within that window, the pending work can still run and access vif/bss data that may already be freed, or send MCU commands while the firmware is not available.  Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown and suspend paths:   - mt7925_mac_reset_work()        (chip reset recovery)  - mt7925e_unregister_device()    (PCIe unbind)  - mt7925_pci_suspend()           (PCIe bus suspend)  - mt7925_suspend()               (mac80211 suspend)  - mt7925u_suspend()              (USB bus / runtime suspend)  This ensures the work is stopped before the device state becomes invalid.