Impact
After initializing the external PHY in the mt7915 wifi driver, a failure in the debugfs or coredump registration path can cause the driver to free the external PHY hardware while it remains registered with mac80211. This use‑after‑free corrupts kernel data structures, leading to instability, a kernel crash, or, in the worst case, an opportunity for an attacker to execute arbitrary code with kernel privileges.
Affected Systems
The vulnerability affects Linux systems that include the mt76 driver for mt7915 wifi hardware. Any kernel that ships the mt7915 driver before the fix is applied is at risk. Specific vendor is Linux, distributed as part of the Linux kernel source tree.
Risk and Exploitability
The CVSS score of 7 indicates a medium severity flaw. The EPSS score of less than 1% shows a low probability of current exploitation, and the flaw is not listed in CISA's KEV catalog. Exploitation would require the attacker to trigger the error path within the driver, which typically requires local access or the ability to influence the driver’s operations. The impact is limited to kernel stability and the potential for privilege escalation if code execution is achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA