Impact
After a full chip reset, the Linux kernel driver for mt76/mt7996 fails to clear an internal flag that marks a link as valid. The replayed Wi‑Fi configuration never recreates critical data structures, so the restarted firmware cannot register the link. The device remains inoperative and a reset sequence that repeats the bug repeatedly drives the firmware into a state where it runs out of index space for multi‑link and virtual‑interface identifiers. The result is a denial of service that can be experienced immediately after a reset or after multiple full‑reset events.
Affected Systems
The affected systems are standard Linux kernel installations that use the mt76 Wi‑Fi driver for Mediatek's MT7996 chip. No product version list is currently published, so any kernel version that includes mt76/mt7996 code may be vulnerable until the race condition is eliminated. There is no vendor‑specific packaging information beyond the generic Linux kernel.
Risk and Exploitability
The EPSS score is below one percent and the vulnerability is not listed in the CISA KEV catalogue, indicating that the likelihood of widespread exploitation is low. The CVSS score is unavailable, but the impact is limited to devices that perform a full chip reset – an operation typically reserved for system boot or reset events and not normally exposed to remote attackers. Consequently, the overall risk is moderate: potential denial of service for Wi‑Fi clients that rely on the affected device, but the attack surface is constrained to privileged users or firmware-level interactions. The denial of service comes from state corruption and resource exhaustion in the driver, rather than remote code execution.
OpenCVE Enrichment