Impact
The vulnerability is a classic Use-After-Free flaw (CWE-367) in the mt76 WiFi driver for the MT7925 chipset. When the device is reset, suspended, or unbound while the delayed work item mlo_pm_work is pending, the work function runs and accesses freed vif/bss structures or attempts to talk to firmware that is no longer present. This can corrupt kernel memory or cause a kernel panic, resulting in a loss of system availability.
Affected Systems
All Linux kernel builds that include the mt76 driver with support for the MT7925 chipset are vulnerable until the patch that adds cancel_delayed_work_sync(&dev reset, unregister, and suspend paths is applied. Any kernel version prior to the commit that fixes this path is affected, regardless of the specific release level, as the vulnerability is tied to the driver code rather than a particular kernel minor version.
Risk and Exploitability
The CVSS score of 7.8 reflects significant severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it is not actively exploited in the wild. An attacker requires local or privileged access that allows triggering a device reset, suspend, or unplug event; from there, the use‑after‑free can lead to a kernel crash or memory corruption, potentially enabling further compromise. The likely attack vector is therefore local or privileged, as no remote exploitation path is described in the input.
OpenCVE Enrichment