Impact
In the Linux kernel, the mt76 wireless driver fails to cancel reset_work and rc_work when a Wi‑Fi device is unregistered. Those workqueue tasks are still flushed by destroy_workqueue after the hardware has already been stopped. If reset_work runs in that window it calls ieee80211_restart_hw and re‑arms mac_work on a device that is no longer registered, while rc_work touches station state that is being torn down. The effect is code executing against a stale, unusable hardware context, which can cause memory corruption, use‑after‑free, and potentially arbitrary kernel code execution.
Affected Systems
This issue affects the Linux kernel, specifically builds that include the mt76 wifi driver. The exact kernel versions are not listed in the advisory; any kernel before the fix that contains the unmodified mt76 driver is potentially vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. The vulnerability requires that an attacker has the ability to trigger a device unregister while the driver is still active, suggesting a local privilege escalation scenario rather than remote exploitation. The CVSS score is not provided in the advisory, so the exact severity cannot be quantified, but the potential for memory corruption and kernel code execution makes it a serious local issue.
OpenCVE Enrichment