Impact
The vulnerability resides in the Linux kernel’s mt76 driver for the mt792x wireless chip. In the SDIO transmit path, if tx_prepare_skb() returns an error, the surrounding socket buffer is not freed, resulting in a kernel memory leak. The condition is triggered when zero‑length frames such as WNM NULL frames are intentionally dropped to avoid hardware transmit hangs. Repeated failures can accumulate unfreed allocations in the kernel, potentially exhausting kernel memory and destabilizing the host, which manifests as a denial‑of‑service scenario that can affect system availability for users and services.
Affected Systems
Linux kernel builds that incorporate the mt76 mt792x driver are affected. No precise kernel release numbers are supplied, so any kernel containing the unpatched mt792x implementation may be vulnerable. Embedded or IoT platforms using MediaTek’s SDIO‑based WiFi chips are likely candidates.
Risk and Exploitability
Based on the description, it is inferred that the leak could be triggered by repeatedly dropping zero‑length frames over the WiFi interface, a remote network‑based vector. The EPSS score is below 1 %, indicating a low probability of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. While the flaw does not require elevated privileges, its impact is significant: kernel memory exhaustion can cause a system crash or reboot. Defenders should treat this as a low‑probability, high‑impact issue that warrants prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA