Impact
The vulnerability is a potential NULL-pointer dereference in the mt76 wireless driver for Intel Connac devices. If the get_he_phy_cap routine returns NULL, the driver code may dereference it without validation, causing the kernel to crash. This loss of kernel stability leads to a denial‑of-service condition on the affected host, disabling network functionality and potentially other kernel services. The impact is system‑wide as it involves core kernel code.
Affected Systems
The affected product is the Linux kernel; the vendor is Linux and the product is Linux:Linux. No specific kernel versions are cited in the data, so all builds containing the insecure mt76 driver code may be vulnerable.
Risk and Exploitability
The exploit would likely target the wireless interface by sending crafted traffic that triggers the NULL pointer condition. The CVSS score of 5.3 indicates a medium severity vulnerability, while the EPSS score is very low (< 1%). Because a kernel crash can be leveraged by an attacker with physical or local network access, the overall risk is considered medium. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA