Impact
The Linux mt7921 Wi‑Fi driver fails to validate a DMA index read from hardware when an Advanced Error Reporting event occurs and the PCIe bus is hung. It can receive a value of 0xFFFFFFFF and use it as a queue index, corrupting the DMA queue state and causing an out‑of‑bounds memory access to q->desc[] or q->entry[]. The invalid access triggers a kernel panic and a system crash, exposing the system to loss of availability and potential influence over integrity. This weakness falls under CWE‑787 and CWE‑20.
Affected Systems
The vulnerability affects any Linux system that includes the mt7921 driver for MT7921 Wi‑Fi hardware. Since the mt76/mt7921 driver is part of the default kernel tree, it is present in most mainstream Linux distributions that ship with that driver. The issue applies to all kernel releases prior to the commit that added PCIe AER handling in the driver.
Risk and Exploitability
The CVSS score of 8.8 categorizes the issue as high severity, while the EPSS score of less than 1% indicates that exploitation is currently unlikely and no widespread attacks have been reported. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a PCIe AER event triggered by malformed Wi‑Fi traffic or firmware manipulation, which then causes the kernel to crash.
OpenCVE Enrichment