Impact
The Linux kernel’s mt76 Wi‑Fi driver contains a race condition in the RXDMAD_C buffer recycling logic. The buffers come from RRO data queues and are tied to a different NAPI context; when recycled directly they can race with the owning NAPI thread, potentially corrupting memory or causing a crash. This concurrency flaw can lead to a denial of service by destabilizing the kernel packet‑handling subsystem.
Affected Systems
Any Linux kernel installation that compiles the mt76 driver without the new non‑direct recycling logic is susceptible. The advisory does not specify exact kernel versions, so all unpatched kernels that still use the original buffer recycling path are at risk. Vendors shipping kernels with mt76 should review release notes to confirm whether the fix has been applied.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity race condition. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability has not been listed in CISA KEV. Based on the description, it is inferred that an attacker might trigger the race by flooding the device with Wi‑Fi frames that queue through the RRO queues; this could be done over a wireless channel or locally. Successful exploitation could crash the kernel, leading to a denial of service.
OpenCVE Enrichment