Impact
A buffer reservation bug in the Linux kernel wireless driver for the MT7996 chipset causes an out‑of‑bounds write when a CA‑shutdown (CSA) beacon countdown is active. The driver emits two countdown TLV entries but reserves space for only one, allowing an eight‑byte overflow that can push the offload command past the maximum allowed size and trigger an skb_over_panic(). This defect results in an operating‑system crash, leaving the affected system in an unreachable state until rebooted. Based on the description, it is inferred that the likely attack vector is an attacker who can instruct the wireless interface to emit a beacon with MBSSID enabled and a near‑maximum beacon template via crafted wireless frames.
Affected Systems
The flaw resides in the core Linux kernel, specifically in the mt76/mt7996 wireless module. All kernel versions that compile this driver without the patch are potentially vulnerable; no explicit affected range is supplied, so any kernel build that contains the unpatched code is at risk.
Risk and Exploitability
The EPSS score is lower than 1 % and the flaw is not listed in the CISA KEV catalog, indicating a low current exploitation probability. Based on the description, it is inferred that the likely attack vector is an attacker who can instruct the wireless interface to emit a beacon with MBSSID enabled and a near‑maximum beacon template via crafted wireless frames. The impact is a denial of service by causing a kernel panic. The lack of a CVSS score in the data set precludes a precise severity figure, but the failure mode suggests a high‑severity outcome locally. The official solution is to apply the kernel patch that reserves space for both countdown TLVs, as referenced in the provided kernel commit URLs.
OpenCVE Enrichment
Debian DLA
Debian DSA