Impact
The vulnerability resides in the Linux wifi driver mt76’s mt7915 module. A TWT flow is appended to the device's list before the firmware agreement is sent. When the MCU rejects the agreement, the error path fails to clear or unlink the flow but leaves it in the list. The flow slot may then be reused and overwritten while still on the list, corrupting the TWT list structure. This memory corruption can destabilize the kernel and, if exploited, could allow an attacker to execute arbitrary code with kernel privileges. The flaw is a classic instance of improper handling of list nodes, leading to list corruption.
Affected Systems
All Linux kernel builds that ship the mt76/mt7915 wifi driver before the patch included in commit c09d1b15 are affected. The specific kernel version is not listed in the data, so any distribution using a kernel containing the unpatched driver must be considered vulnerable until the fix is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need local access to the device or the ability to send crafted TWT requests over WiFi, implying that the attack vector is local or possibly remote if the driver is exposed to network traffic. The exploit would require triggering the error path and manipulating the TWT flow, which is feasible given the driver’s behavior described in the commit messages.
OpenCVE Enrichment
Debian DLA
Debian DSA