Impact
The Linux kernel’s mt76 driver for Wi‑Fi hardware allows an out‑of‑range array index to be used when setting the link identifier. The affected function reads past the end of the link array, accessing an adjacent data field that holds off‑channel link information. This flawed bounds check can cause the kernel to read invalid memory locations, potentially corrupting internal state or leaking sensitive information. If abused, an attacker could trigger kernel instability or gain unintended access to control‑information, resulting in a denial of service on the affected system.
Affected Systems
All Linux kernel installations that include the mt76 driver for MT76xx wireless adapters are vulnerable. The issue is present in any kernel version that ships with the unpatched driver implementation; however, specific affected versions are not enumerated in the advisory. Users of distributions that package a recent kernel with this driver should verify whether the patch has been applied, as the flaw exists in the core Wi‑Fi stack.
Risk and Exploitability
The advisory lists an EPSS score of less than 1%, indicating a low probability of exploitation at the current time, and the vulnerability is not in the CISA KEV catalog. Nonetheless, because the flaw can be triggered by calls made during normal Wi‑Fi operation, an attacker with network or physical proximity could exercise the vulnerable functions through crafted frames or device activity. The lack of a public exploit and low EPSS score suggest limited immediate risk, but mitigations should still be applied promptly, as the flaw has the potential for local privilege escalation or instability.
OpenCVE Enrichment