Impact
The vulnerability occurs when the Wi‑Fi driver mt7915 fails to release a reference to the hif2 structure during IRQ initialization. The reference is only properly released on certain error paths that rely on a device field that is not yet set, causing the reference to leak when pci_alloc_irq_vectors() or devm_request_irq() fails. The leak can create a resource exhaustion problem and potentially destabilize the kernel, but it does not allow arbitrary code execution or privilege escalation.
Affected Systems
The affected product is the Linux kernel, specifically those releases that include the mt76 mt7915 Wi‑Fi driver before the fix was applied. No exact version range is provided, so any system running an unpatched kernel that incorporates this driver could be impacted.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of public exploitation. The flaw requires the driver to be probed, which typically occurs during system boot or when enabling Wi‑Fi, and therefore is a local privilege requirement. The impact is limited to resource exhaustion and potential denial of service rather than remote code execution or data breach.
OpenCVE Enrichment
Debian DLA
Debian DSA