Impact
An out‑of‑bounds read in the Linux kernel wifi driver mt76/mt7996 occurs because the default EEPROM firmware is parsed and copied as a full EEPROM without verifying its size. If the firmware file is truncated, the driver can read beyond the allocated buffer during variant validation or fallback copying, triggering a kernel fault and a system crash. The flaw leads to a loss of availability only; there is no evidence of code execution or information disclosure.
Affected Systems
The vulnerability affects any Linux system that includes the mt76/mt7996 driver module, which is used by MediaTek MXMP/MT7996 wireless chipsets. When the module loads and processes the default EEPROM firmware, systems that provide or contain a truncated firmware file are exposed. The impact is independent of the Linux distribution because the problematic module is part of the kernel itself.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity, while the EPSS score of less than 1% indicates a very low but non‑zero likelihood of active exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the most realistic attack vector requires an attacker who can supply or modify the EEPROM firmware used by the driver—such as through a firmware update process, misconfigured device, or malicious firmware file placed on the system. Exploitation leads solely to a system crash and loss of service, with no documented pathway to higher‑privilege execution.
OpenCVE Enrichment
Debian DSA