Impact
The vulnerability originates from the mt76 driver for the mt7996 Wi‑Fi chipset in the Linux kernel. During a full reset the driver queues non‑default virtual interface links for delayed freeing while the wireless client ID array still contains pointers to the data embedded in those links. A subsequent reset routine dereferences those stale pointers and performs cleanup on memory that may have already been reclaimed, creating a use‑after‑free condition that can corrupt kernel memory. If an attacker can cause a reset sequence after the grace period, they may be able to trigger a kernel crash or run arbitrary code with kernel privileges.
Affected Systems
This flaw affects the Linux kernel, specifically builds that include the mt76 driver used for mt7996 Wi‑Fi chips. No specific kernel versions are listed in the data, so the issue may exist in any open‑source distribution that compiles the current driver source.
Risk and Exploitability
The attack vector is likely local or remote control of the Wi‑Fi interface that can trigger full resets; however the data does not provide explicit details, so this is inferred. The EPSS score is less than 1 %, and the vulnerability is not listed in CISA KEV, indicating low to moderate exploitation likelihood. Nevertheless, because the flaw can corrupt kernel memory, it is considered a high severity issue that could allow privilege escalation or denial of service if an attacker gains the ability to influence device reset operations.
OpenCVE Enrichment