Impact
The vulnerability in the Linux kernel’s mt76 Wi‑Fi driver, specifically the mt7996 sub‑driver, is a race condition that occurs when the driver disables the transmit worker during a software error recovery (SER). If a channel change is initiated while the reset routine holds the worker in a parked state, the worker can be unparked and the MT76_RESET flag cleared after the DMA ring reset. This race can corrupt DMA rings and other driver descriptors, potentially leading to kernel data corruption or a system crash.
Affected Systems
The flaw affects Linux kernels that ship with the mt76 driver for mt7996 hardware. The affected products are not limited to a specific vendor; any distribution or custom kernel that includes the mt76/mt7996 driver code is potentially vulnerable. No specific version ranges are listed in the CNA data, so all kernel versions containing the unpatched mt76 code should be considered at risk.
Risk and Exploitability
The CVSS base score is 8.8, indicating a high severity threat. The EPSS score is reported as less than 1 percent, implying a low probability that the vulnerability has been actively exploited. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is local, requiring the attacker to trigger a channel switch during a reset sequence (e.g., through malformed firmware or driver use). Because the condition involves race between kernel threads, it is difficult to reproduce reliably, further lowering the exploitability risk.
OpenCVE Enrichment