Impact
The issue arises when the mt7915 Wi‑Fi driver performs a double initialization of the HIF2 interface on non‑WED paths. The init function is called unconditionally and again inside a conditional block, causing the global hif_idx counter to increment twice, the PCIe RECOG_ID register to be written twice, and an extra reference to the device object to be obtained. Because the corresponding release path removes only a single reference, a reference leak occurs. Although the vulnerability is not directly exploitable via user input, the leaked reference can accumulate over time and exhaust kernel reference counts or memory, potentially destabilizing the Wi‑Fi subsystem and impacting availability.
Affected Systems
All Linux kernel builds that incorporate the mt7915 driver without the commit that fixes the double‑initialization logic are affected. The flaw resides in the mt76 driver code family and is present in any distribution kernel that has not yet applied the specific patch commit. Users should verify whether their kernel version contains the committed fix or any later kernel release that implements it.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low probability of exploitation in the wild, and the CVE is not listed in the CISA KEV catalog. The flaw requires kernel‑level execution to trigger the double initialization, making it relevant mainly to local privileged users or through a local privilege escalation vector. If successfully triggered, the resulting reference leak and duplicated register writes could degrade system stability or lead to resource exhaustion, thereby impacting availability of the Wi‑Fi subsystem.
OpenCVE Enrichment
Debian DLA
Debian DSA