Impact
In the Linux kernel’s mt76 Wi‑Fi driver, a logic flaw in the handling of Receive‑Rx Order (RRO) 3.0 caused frames to be placed in an incorrect queue. The frames were never scheduled for immediate processing and sat on the data queue until its associated NAPI poll happened to run, leading to delayed delivery and out‑of‑order reception. This defect could degrade network performance or cause packet loss, potentially interrupting time‑critical traffic and creating a denial‑of‑service condition within the device’s wireless subsystem. The vulnerability arises from improper queue management and concurrency handling, highlighting a weakness where data is processed out of sequence.
Affected Systems
This flaw affects Linux kernel builds that include the mt76 driver with RRO 3.0 support. All Linux distributions shipping a kernel that bundles the mt76 driver, regardless of vendor, are potentially impacted, as the CPE indicates the generic Linux kernel and the vendor list includes Linux:Linux. No specific version ranges are supplied in the CNA data, but the fix is committed to the kernel source via the three Git references provided.
Risk and Exploitability
The exploit probability is very low, with an EPSS score of < 1 %. The vulnerability is not listed in CISA’s KEV catalog and no public exploit has been reported. Nonetheless, because the flaw can stall and reorder transmit data, a determined attacker who can send crafted traffic to a device using RRO 3.0 may be able to induce a loss of service or degrade performance. The risk is moderate due to the lack of a known CVSS score, but the potential impact on stability makes remediation advisable.
OpenCVE Enrichment