Impact
When the mt76 Wi‑Fi driver attempts to allocate memory or map I/O resources, failures in pcim_iomap_region() or devm_kmemdup() cause the code to return without cleaning up previously allocated device structures and interrupt vectors. This leaves hidden resource allocations lingering in the kernel. Over time, repeated probe errors can deplete available memory or interrupt vectors, leading to driver instability or kernel crashes. The vulnerability is a classic memory/resource leak described by CWE‑772.
Affected Systems
Linux kernel systems that build and load the mt76 driver with the mt7921 module are affected. All distributions employing the default kernel configuration before the commit that introduced the fix—e.g., any kernel version older than the commit identified by the hash 346dac3—may run the vulnerable driver. Users of custom kernels that include the legacy mt76 stack likewise remain exposed. The specific vendor products are not named, but the issue is limited to any Linux environment where the mt76 Wi‑Fi driver is active.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% signals a low likelihood of widespread exploitation. The vulnerability is not present in CISA’s KEV catalog. Exploitation would require an attacker to induce frequent allocation failures, a scenario that is unlikely under normal operation but could occur if hardware faults or aggressive probing are introduced. Under such conditions, the kernel could exhaust resources, resulting in a denial‑of-service attack. Immediate patching alleviates the risk.
OpenCVE Enrichment