Impact
When the mt7915 driver attempts to add a wireless interface, a failure in the internal allocation routine leaves stale state in kernel data structures. The driver does not clear the vif_mask, omac_mask, or monitor_vif pointers it set before the failure, and the accompanying firmware device information remains registered. This results in a use‑after‑free condition that can be triggered if an attacker can cause the interface addition to fail, allowing dereferencing of a stale reference and potentially arbitrary code execution with kernel privileges.
Affected Systems
The vulnerability is confined to the Linux kernel’s mt76/mt7915 wireless driver module. Any installation of the Linux kernel that contains this driver prior to the fix is affected. No vendor‑specific version range is published, so all kernels that include the mt7915 driver before the patch are considered at risk.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the issue is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. However, the kernel use‑after‑free severity is high; if an attacker can stimulate a failed add_interface operation—either locally by manipulating network configuration, or remotely if monitor mode or Wi‑Fi management controls are exposed—privilege escalation to kernel level becomes possible. The attack vector is inferred based on the need to trigger interface creation failure. Existing conditions for exploitation are narrow, but the impact is severe if successfully achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA