Impact
A kernel driver for Wi‑Fi hardware incorrectly handled a case where a peer's VHT/HE MCS map contained no supported spatial streams, causing a loop to exit with nss equal to zero and the function to return the unsigned value 255. This value was then written into the firmware's beamforming configuration, potentially corrupting the device's operational parameters. The patch restricts the result to zero, preventing bad data from propagating. The flaw represents an integer underflow that could lead to corrupted firmware settings, which might result in degraded Wi‑Fi performance or a denial of service on the affected device.
Affected Systems
The vulnerability impacts the Linux kernel's mt76 driver for the mt7915 Wi‑Fi chipset, which is used in Linux distributions that include this driver. All kernel versions prior to the applied patch that ship the mt76 module are potentially affected. Specific vendor or distribution names are not listed, but the issue applies to any Linux system running the offending driver version.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The EPSS probability is listed as less than 1 %, implying a low likelihood of exploitation at present, and the vulnerability is not included in CISA’s KEV catalog. Exploitation would require interaction with the Wi‑Fi hardware and likely a malicious or compromised firmware payload, so the attack vector is inferred as a local or firmware‑based vector rather than a straightforward remote one. Nonetheless, because the flaw corrupts firmware settings, it could precipitate service disruption if triggered. The existing mitigation is to apply the kernel patch that clamps the value to zero.
OpenCVE Enrichment
Debian DLA
Debian DSA