Impact
A malicious or malfunctioning Wi‑Fi device can report an arbitrary destination address for an EFUSE block copy, and the Linux kernel driver fails to limit this offset. The copy operation therefore writes up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past the driver’s internal EEPROM buffer, corrupting kernel memory. This corruption can lead to privilege escalation, arbitrary code execution or kernel panic depending on the attacker’s ability to control the data written.
Affected Systems
Linux systems that load the mt76 Wi‑Fi driver with the mt7996 controller are affected. This includes devices that use the mt7996 chipset and run a kernel image that has not incorporated the patch that bounds the EEPROM address before the copy.
Risk and Exploitability
The CVSS base score of 8.8 points to a high‑severity vulnerability, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely a malicious EFUSE request from a compromised or rogue Wi‑Fi device that supplies an out‑of‑bounds address, which then triggers the out‑of‑bounds write and the associated kernel memory corruption.
OpenCVE Enrichment