Impact
The Linux kernel mt76 driver for MT7996 contains a logic flaw: if the MLD_ID field in a transmit descriptor is neither the primary link id nor the secondary link id, the firmware enters a busy loop and repeatedly logs "ERROR!! NO PAUSE...". This flaw results from improper input validation (CWE-20) and effectively freezes the networking stack for the affected device.
Affected Systems
This vulnerability affects any Linux kernel that includes the mt76 driver for MT7996 hardware. The vendor list indicates generic Linux kernels, and no specific kernel version numbers are listed. The patch is introduced in the commits referenced by the provided git URLs; kernels lacking this commit remain vulnerable.
Risk and Exploitability
The EPSS score is reported as below 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is not provided; the flaw results in a local denial of service that requires delivery of frames with an invalid MLD_ID. Based on the description, it is inferred that an attacker would need local or privileged access to inject such frames to the Wi‑Fi adapter, as remote injection would depend on other network‑layer weaknesses not described here. The overall risk remains low, but the issue should be remediated promptly.
OpenCVE Enrichment