Executive brief
A vulnerability in the MediaTek mt7921 Wi-Fi driver within the Linux kernel can cause a firmware crash when the device is operating as a wireless access point. This occurs when a connecting station is assigned an identification number (AID) higher than 20, which can happen with certain modified network management software. An exploit results in a denial of service, requiring a system or driver restart to restore wireless connectivity.
Technical details
A vulnerability in the mt76 mt7921 driver for MediaTek Wi-Fi chipsets (including 7922 hardware) allows for a firmware crash. The root cause is a lack of bounds checking on the station Association Identifier (AID) within the mt7921_mac_sta_add and mt7921_mac_sta_event functions. When the driver is configured in Access Point mode (IFTYPE_AP) and a station attempts to associate with an AID greater than 20, the firmware crashes. This was specifically observed when using modified hostapd versions that allocate AIDs starting at 65. The fix introduces a hard upper limit (MT7921_MAX_AID) of 20 to prevent out-of-bounds values from reaching the firmware.
Affected products
- Linux Linux Kernel 5.12 to 7.1
Timeline
- 2026-06-26: advisory
- 2026-06-26: disclosed