Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7921: fix resource leak in probe error path

When pcim_iomap_region() or devm_kmemdup() fail, the code returns
directly without cleaning up previously allocated resources:
- mt76_device allocated by mt76_alloc_device()
- pci irq vectors allocated by pci_alloc_irq_vectors()
Fix this by jumping to the existing error cleanup path instead of
returning directly.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

When the mt76 Wi‑Fi driver attempts to allocate memory or map I/O resources, failures in pcim_iomap_region() or devm_kmemdup() cause the code to return without cleaning up previously allocated device structures and interrupt vectors. This leaves hidden resource allocations lingering in the kernel. Over time, repeated probe errors can deplete available memory or interrupt vectors, leading to driver instability or kernel crashes. The vulnerability is a classic memory/resource leak described by CWE‑772.

Affected Systems

Linux kernel systems that build and load the mt76 driver with the mt7921 module are affected. All distributions employing the default kernel configuration before the commit that introduced the fix—e.g., any kernel version older than the commit identified by the hash 346dac3—may run the vulnerable driver. Users of custom kernels that include the legacy mt76 stack likewise remain exposed. The specific vendor products are not named, but the issue is limited to any Linux environment where the mt76 Wi‑Fi driver is active.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% signals a low likelihood of widespread exploitation. The vulnerability is not present in CISA’s KEV catalog. Exploitation would require an attacker to induce frequent allocation failures, a scenario that is unlikely under normal operation but could occur if hardware faults or aggressive probing are introduced. Under such conditions, the kernel could exhaust resources, resulting in a denial‑of-service attack. Immediate patching alleviates the risk.

Generated by OpenCVE AI on August 22, 2026 at 02:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that contains the mt76/mt7921 driver fix (e.g., the commit referenced by 346dac3 or a newer mainline release).
  • Restart the system or reload the driver so the patched code takes effect.
  • If an immediate kernel upgrade is not feasible, disable the mt76 driver or disconnect the Wi‑Fi hardware to prevent repeated probe failures until the patch is applied.

Generated by OpenCVE AI on August 22, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix resource leak in probe error path When pcim_iomap_region() or devm_kmemdup() fail, the code returns directly without cleaning up previously allocated resources: - mt76_device allocated by mt76_alloc_device() - pci irq vectors allocated by pci_alloc_irq_vectors() Fix this by jumping to the existing error cleanup path instead of returning directly.
Title wifi: mt76: mt7921: fix resource leak in probe error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:17:16.898Z

Reserved: 2026-08-15T05:44:03.884Z

Link: CVE-2026-74326

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:33.260

Modified: 2026-08-17T06:19:27.033

Link: CVE-2026-74326

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74326 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T02:45:03Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime