Impact
In the Linux kernel, the mt7925 wireless driver schedules a delayed work item, mlo_pm_work, during multi‑link power‑save initialization. The driver never cancels this work when the device is stopped. If the module is torn down within the five‑second window, the timer fires after the teardown, attempting to queue work onto a workqueue that has already been destroyed, producing a kernel warning and potentially causing a crash. This flaw is a resource‑management error, classified as CWE‑763: Information Leak Through Improper Safe Resource Release.
Affected Systems
All Linux kernel installations that include the mt7925 Wi‑Fi driver – both the PCIe and USB variants – are affected. The issue resides within the kernel’s wireless stack, specifically the mt76 subsystem; any hardware that ships with this driver bundled in the kernel image is impacted.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderate severity. The EPSS score of <1% indicates a very low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it appears required to force the driver to stop during the five‑second delay window to trigger the fault; thus the practical attack surface is limited to an insider or attacker with physical or root access. No remote trigger or privilege‑elevation path exists, keeping the overall risk comparatively low.
OpenCVE Enrichment