Impact
A race condition in the Linux kernel wifi driver mt7915 allows the wcid mask to be cleared without holding the necessary mutex and before the RCU pointer is cleared. The mask is a non‑atomic read‑modify‑write bit shared with allocators that run under the same mutex. When the mask is cleared prematurely, a concurrent add_interface or sta_add operation on another band can leak a wcid index or hand it out twice, and a new allocation can reuse the index and publish its wcid only to be null‑assigned immediately afterwards. This misuse of the mask can corrupt driver data structures, potentially causing a kernel panic or disrupting Wi‑Fi traffic, resulting in a denial of service to the affected system.
Affected Systems
The vulnerability is present in the Linux kernel, affecting all releases that include the mt76/mt7915 driver module before the patch. The exact kernel versions are not specified in the advisory, so any installation using this Wi‑Fi driver should consider updating.
Risk and Exploitability
The EPSS score is reported as <1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The attack vector is most likely local or confined to systems that can manipulate the Wi‑Fi driver (e.g., via physical or software control of the interface). An attacker with sufficient privileges to interact with the driver would need to trigger a race between interface removal and station addition to exercise the flaw. The impact, if successfully exploited, would be a kernel crash or loss of Wi‑Fi connectivity, not remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA