Impact
An out-of-bounds array access exists in the Linux kernel’s mt76 Wi‑Fi driver (mt7996_tx()). When a link ID is unspecified, the function substitutes the value 0xf (IEEE80211_LINK_UNSPECIFIED) and uses it unchecked as an array index into structures that hold only 15 entries. This unchecked index could read or alter memory beyond the intended bounds, potentially corrupting kernel state or exposing kernel data. The description does not indicate a write primitive or guarantee denial of service, but the unchecked access represents a kernel memory integrity issue.
Affected Systems
The flaw affects the mt76 Wi‑Fi driver for mt7996 hardware within the Linux kernel. No specific kernel version is referenced, so any kernel containing the vulnerable code before the patch may be susceptible. The fix is present in the stable tree and distributed in kernel releases updated after the patch commit.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported. Likely the attack vector would involve sending crafted Wi‑Fi frames that trigger the driver to use the unspecified link ID, but such exploitation has not been demonstrated. Consequently, the risk remains theoretical, though the kernel could become unstable under malicious traffic once the vulnerability is present.
OpenCVE Enrichment