Skip to content
VulniPulse
UnratedNETGEAR

Advisory [CVE-2026-80825] NETGEAR: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there

This security NETGEAR advisory covers CVE-2026-80825 affecting NETGEAR.

CVE-2026-80825 Published Sep 4, 2026Updated by vendor Sep 4, 2026
Related products & platforms
NETGEARUnclassified
Open vendor advisory

Android app · Google Play

Monitor future NETGEAR CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb

mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already

there. That holds for locally generated traffic, where mac80211

reserves hw->extra_tx_headroom, but forwarded frames are sent through ieee80211_8023_xmit(), which does not reserve it.

Bridge a wired interface to an mt7925u AP and the first forwarded frame that arrives

short panics the kernel:

skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1 kernel BUG at net/core/skbuff.c:212!

Call trace: skb_panic+0x58/0x60 (P)

skb_push+0x58/0x60 mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common]

mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb] __mt76_tx_queue_skb+0x54/0xe8 [mt76]

mt76_txq_schedule.part.0+0x204/0x478 [mt76] mt76_txq_schedule_all+0x50/0x80 [mt76]

mt792x_tx_worker+0x68/0x100 [mt792x_lib] __mt76_worker_fn+0x84/0x150 [mt76]

Whether a given setup hits it depends on how much headroom the ingress netdev leaves in its rx skbs.

Reproduced on a Raspberry Pi 5 bridging onboard ethernet to a Netgear A9000; originally reported on an MT7986

router running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet),

which leaves more headroom, helped narrow the trigger to the ingress path.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

NVD record · medium-confidence parse· fetched 1 hour ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

NVD record · medium-confidence parse· fetched 1 hour ago·verify at source

Mitigation

The source record does not include mitigation steps. That is not a statement that no fix exists — read the vendor advisory below for the authoritative guidance.

NVD record · medium-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.