Impact
The Linux kernel’s mt76 driver for Marvell mt7996 and mt7992 Wi‑Fi chipsets has a flaw that leaks a DMA mapping each time an AddBA request frame is processed. Specifically, the weakness is a buffer exhaustion issue (CWE‑771) created because when the frame uses a MAC‑TXP descriptor the cleanup code fails to unmap the associated transmission buffer. The leaked mapping accumulates over repeated association or disassociation events, potentially exhausting the kernel’s WED swiotlb pool and causing subsequent DMA operations to fail, which can disable the WLAN subsystem and other on‑SoC consumers. This bug represents a medium‑severity flaw (CVSS 5.3) that can lead to denial of service for Wi‑Fi operations.
Affected Systems
All Linux kernels that load the mt76 wireless driver and support the Marvell mt7996 or mt7992 chip versions of the driver before the fix referenced in the commit logs; the fix is applied in later kernel releases. Devices running patched kernel or driver versions are no longer affected.
Risk and Exploitability
The CVSS score of medium severity, and the EPSS score of <1% indicates a very low probability of exploitation, though the flaw could be abused if an attacker can induce frequent Wi‑Fi association or disassociation events. The flaw is not immediately exploitable from a remote arbitrary‑code perspective; the attacker would need to deplete the DMA mapping store. Based on the description, it is inferred that the likely attack vector is an entity that can induce the device to perform repeated client reconnects, for example a malicious Wi‑Fi client capable of joining and leaving the network cyclically. While the flaw is not listed in the CISA KEV catalog, it could cause severe service disruption if an attacker can generate the required traffic pattern. Because the condition depends on workload, the risk timeline is continuous exposure rather than a one‑shot vulnerability. Security teams should monitor DMA mapping usage and consider disabling WED or limiting client churn as temporary mitigations until a kernel update is available.
OpenCVE Enrichment