Impact
The Linux kernel’s mt76 Wi‑Fi driver for MT7996 hardware incorrectly uses a 2‑bit descriptor field to index the phys[] array without validating the value. The index can be 0‑3, but phys[] has a size of 3, so an index value of 3 or a reserved value can address memory beyond the array or a NULL pointer. This out‑of‑bounds access can trigger a kernel fault, causing a panic and a complete loss of system availability. Because the fault occurs during packet reception, no code execution or privilege escalation is required; the primary impact is a denial of service.
Affected Systems
Systems running a Linux kernel that incorporates the mt76 driver for MT7996 wireless adapters—including many consumer and industrial devices—are affected. The vulnerability applies to all kernel releases that include the unpatched mt76 source before the fix commit, and therefore applies to any active installation of such kernels until updated.
Risk and Exploitability
The EPSS score listed as <1 % and the absence from the CISA KEV catalog indicate a low probability of exploitation in the wild. An attacker would need to transmit malicious Wi‑Fi traffic that contains an out‑of‑bounds band index value. While no public exploits or proof‑of‑concepts have been reported, the vulnerability can be triggered by any active receiver on the air, making it feasible for a local or remote adversary to induce a kernel crash if the system is within range of a traffic source.
OpenCVE Enrichment
Debian DLA
Debian DSA