Impact
The Wi‑Fi driver mt76/mt7915 performs an EFUSE copy into an internal EEPROM buffer using an offset supplied by the device firmware, without validating that malicious or malfunctioning device can report an address that causes a 16‑byte out‑of‑bounds write, corrupting kernel memory. If the write corrupts critical data structures or function pointers, an attacker could achieve arbitrary code execution at the kernel privilege level. The vulnerability is therefore a kernel memory corruption flaw with potential for privilege escalation.
Affected Systems
Linux kernel builds that include the mt76/mt7915 Wi‑Fi driver. The advisory applies to all versions that have not yet integrated the fix.
Risk and Exploitability
The flaw allows an attacker controlling the Wi‑Fi adapter firmware to supply an arbitrary offset. The driver copies a fixed EFUSE block into its eeprom.data buffer at the reported offset without validating bounds, which results in a 16‑byte out‑of‑bounds write. EPSS probability (<1 %). The CVSS score of 8.8‑level code execution. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment