# CVE-2026-89523

## Summary

- **CVE ID:** CVE-2026-89523
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: cancel pending mlo_pm_work

If the device is reset, suspended or unregistered within that window,
the pending work can still run and access vif/bss data that may already
be freed, or send MCU commands while the firmware is not available.

Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown
and suspend paths:

 - mt7925_mac_reset_work()        (chip reset recovery)
 - mt7925e_unregister_device()    (PCIe unbind)
 - mt7925_pci_suspend()           (PCIe bus suspend)
 - mt7925_suspend()               (mac80211 suspend)
 - mt7925u_suspend()              (USB bus / runtime suspend)

This ensures the work is stopped before the device state becomes
invalid.

## Affected Products

- Linux — Linux (276a568832577c81ec90b62dc506bbdc3781ca46)
- Linux — Linux (74eb79258bfd5f2ffe6d26a09c898992b2afa1ce)
- Linux — Linux (6.14.3)
- Linux — Linux (6.15)
- Linux — Linux (0)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/5be6d02837d418bc6c805b5cab1b338de6de9ca7)
- [CNA](https://git.kernel.org/stable/c/c5e073f2fbfd34d22099a50d96f60990799753e2)
- [CNA](https://git.kernel.org/stable/c/2889e84282dda147f10b10d94cf0efd90a349c53)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._