cbcvebase.
CVE-2025-68738
published 2025-12-24

CVE-2025-68738: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix null pointer deref in mt7996_conf_tx() If a link does not have an…

PriorityP419high7.2
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix null pointer deref in mt7996_conf_tx() If a link does not have an assigned channel yet, mt7996_vif_link returns NULL. We still need to store the updated queue settings in that case, and apply them later. Move the location of the queue params to within struct mt7996_vif_link.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= c0df2f0caa8dde0d50f36649ee28a54c5079281b < 96841352aaba7723c20afb3a5356746810ef819896841352aaba7723c20afb3a5356746810ef8198
linuxlinux>= c0df2f0caa8dde0d50f36649ee28a54c5079281b < b8f34c1c5c4f5130c20e3253c95ba1d844d402b9b8f34c1c5c4f5130c20e3253c95ba1d844d402b9
linuxlinux>= c0df2f0caa8dde0d50f36649ee28a54c5079281b < 79277f8ad15ec5f255ed0e1427c7a8a3e94e7f5279277f8ad15ec5f255ed0e1427c7a8a3e94e7f52
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.14.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.