Impact
The patch addresses a bug in the mt76 Wi‑Fi driver where the copy helper functions iterated up to an aligned length rather than the actual buffer size, allowing a read or write beyond the bounds of the source or destination buffers. This behavior can corrupt kernel memory, potentially exposing sensitive data or enabling an attacker to execute arbitrary code with kernel privileges.
Affected Systems
The vulnerability is present in the Linux kernel’s mt76 Wi‑Fi driver, which is distributed with many Linux distributions. Any system running a kernel that includes the unpatched mt76 driver is affected; the specific kernel versions are not listed in the data, so all installations that have not incorporated the fix are potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. However, the error occurs in kernel code and could lead to memory corruption if an attacker can influence the driver’s data length calculations. Exploitation would most likely require local access or the ability to load malicious kernel modules, so the threat is moderate to high for systems that allow such access. The lack of a CVSS score in the data means the exact severity is not quantified, but the nature of the flaw suggests it could be treated as a serious kernel security issue.
OpenCVE Enrichment