Impact
Based on the description, a race condition in the Linux kernel Wi‑Fi driver mt76 triggers a use‑after‑free in the mt792x series during station removal. When the receiver poll function dispatches, the driver accesses a stale pointer to the station’s wcid, which can corrupt memory or cause a kernel panic. An attacker who can send crafted frames to the affected device may provoke the flaw, potentially leading to a crash or, if memory corruption is hijacked, kernel‑level code execution.
Affected Systems
The vulnerability applies to all Linux kernel builds that include the mt76/mt792x Wi‑Fi driver. No specific kernel version is supplied; any in‑use kernel that supports these drivers is potentially susceptible. Updating to a kernel snapshot that contains the committed patch fixes the issue.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is considered high severity. The EPSS score is reported as under 1 %, indicating a very low current exploitation probability. It is not yet listed in the CISA KEV catalog. It is inferred that the likely attack vector is remote via malicious Wi‑Fi packets; a local attacker with physical radio access could also exploit the flaw. Without a publicly available exploit, the risk is moderate, but the potential for privilege escalation warrants timely mitigations.
OpenCVE Enrichment
Debian DLA
Debian DSA