Impact
In the Linux kernel's mt76 wireless driver for devices such as the MT7612U, a corrupted frame received in monitor mode with the fcsfail filter can report an MPDU length greater than the buffer size. The driver correctly discards the frame, but the early code wrapped the discard in a WARN_ON_ONCE. When the global kernel setting panic_on_warn is enabled, this single warning taints the kernel and triggers a panic on the first occurrence, bringing the system to a halt. The flaw therefore allows a remote attacker who can transmit malformed wireless packets to force a kernel panic and disrupt service, but does not enable privilege escalation or data exfiltration.
Affected Systems
Affected systems are Linux kernel versions that include the mt76 driver path used by the MT7612U and similar devices running in monitor mode with fcsfail enabled. The patches that remove the WARN invoke the same logic as an earlier commit that silenced the warning in adjacent paths. No specific vendor names beyond “Linux” appear in the CNA fields, and the precise kernel versions before the change are not enumerated in the data.
Risk and Exploitability
The CVSS vector is unreported, but the EPSS score is below 1% and the vulnerability is not in the CISA KEV catalog, suggesting low exploitation probability at present. However, the impact of a kernel panic is severe, giving the attacker full denial‑of‑service over a network. The likely attack path is through the wireless interface, sending crafted frames while monitor mode and fcsfail are active; privileged kernel settings (panic_on_warn) are not required. Given the low EPSS, the risk remains moderate, but potential for widespread disruption warrants prompt action.
OpenCVE Enrichment
Debian DLA
Debian DSA