Executive brief
A memory leak vulnerability was identified in the Linux kernel's MediaTek Wi-Fi driver (mt76). This issue occurs when certain wireless connection requests fail, causing the system to fail to release allocated memory. Over time, repeated occurrences could lead to system instability or performance degradation as available memory is exhausted.
Technical details
A memory leak exists in the mt76 driver within the Linux kernel's wireless subsystem. The function mt76_connac_mcu_alloc_sta_req() allocates a socket buffer (skb) that is intended to be freed by mt76_mcu_skb_send_msg(). However, if intermediate functions such as mt76_connac_mcu_sta_wed_update() or mt76_connac_mcu_sta_key_tlv() return an error, the execution path exits without freeing the allocated skb. This vulnerability affects MediaTek Wi-Fi chipsets using the mt76 driver, including mt7915 and mt7925. The issue has been resolved by adding explicit dev_kfree_skb() calls in the affected error paths.
Affected products
- Linux Linux Kernel 5.18 to 7.0.10
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory