Impact
In the Linux kernel’s mt76 Wi‑Fi driver, the routine mt76_switch_vif_chanctx() failed to handle channel context switching when different radios shifted between bands in quick succession. The bug allowed mismatched channel contexts to be applied, which could trigger undefined behavior and cause the driver—and consequently the kernel—to crash. Because a kernel panic terminates all network activity, the primary impact is a denial‑of‑service to wireless clients on the affected device.
Affected Systems
The issue targets the Linux kernel’s mt76 wireless driver component, which is included in many mainstream Linux distributions. Any system running a kernel that has not been updated to a revision incorporating the patch commit referenced in the advisory is potentially exposed. No specific release numbers are listed, so all kernels with an unpatched mt76 driver are in scope.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity DoS risk. The EPSS metric is below 1%, reflecting a very low likelihood of observed exploitation in the wild, and the vulnerability is not currently cataloged in the CISA KEV list. Exploitation requires a local user with the ability to trigger rapid, cross‑band channel switches—such as a malicious application or a user with network‑driver control—making the attack vector local and privileged. No remote‑network exploitation is documented or implied by the CVE text.
OpenCVE Enrichment