Impact
The flaw occurs in the Linux kernel’s mt76 driver for the MT7996 Wi‑Fi chipset. The firmware TLV parsing loop advances the offset by the length field without checking that the length is non‑zero or within bounds. A zero‑length TLV can therefore cause the loop to never progress, hanging the CPU while the device is probed. The driver also reads a 32‑bit payload without bounds checking, potentially allowing out‑of‑range reads. The net effect is a CPU‑bound denial of service that can stall system boot or network operation while the driver hangs.
Affected Systems
The vulnerability affects Linux kernel users running the mt76 driver for the MediaTek MT7996 Wi‑Fi module. Any kernel version that contains the unpatched mt76 mt7996 code prior to the recent commit is susceptible. No specific version range is listed, so all builds that include this driver are potentially at risk.
Risk and Exploitability
The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. The attack vector appears local to the device; an attacker would need to supply a firmware response containing a malformed TLV during device probe or a malicious rebuild of the firmware. If successful, the firmware parsing loop would spin forever, consuming CPU resources and leading to a denial of service. Because the immediate impact is limited to a device probe, widespread network exploitation is unlikely without physical access or firmware control.
OpenCVE Enrichment
Debian DLA
Debian DSA