Junglewise Threat Intelligence

CVE-2025-39862: Linux Kernel mt7915 Wi-Fi driver list corruption during hardware restart

CVE-2025-39862 · Severity: high · CVSS 8.8 · Published 2025-09-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's MediaTek Wi-Fi driver could allow an attacker to cause system instability or potentially gain unauthorized access. The issue occurs when the Wi-Fi hardware restarts, failing to properly clear internal lists and leading to memory corruption. This could result in a complete loss of network availability or compromise of the device's data integrity.

Technical details

A vulnerability exists in the mt76 driver for MediaTek mt7915 Wi-Fi chipsets due to improper list management during a hardware full reset. When the hardware restarts, wireless client identifiers (wcids) are not properly cleared from internal lists before the stations are recreated. This leads to list corruption and potential out-of-bounds writes (CWE-787). An attacker within radio range (adjacent network) could potentially exploit this to cause a denial-of-service or execute arbitrary code. The fix involves explicitly clearing wcid entries and resetting device lists in mt76_reset_device before calling hardware restart functions.

Affected products

  • Linux Linux Kernel 6.2 to 6.16.6

Timeline

  • 2025-08-27: patched: Initial patch authored by Felix Fietkau
  • 2025-09-19: disclosed: CVE published by kernel.org

References

Related threats