Junglewise Threat Intelligence

CVE-2026-63866: Linux Kernel mt7996 Wi-Fi driver pointer mismanagement in station deinit

CVE-2026-63866 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's MediaTek Wi-Fi driver (mt7996) where internal connection identifiers were not properly cleared during disconnection. This could lead to system instability or memory management issues when wireless devices connect and disconnect from the network. The issue has been resolved in recent kernel updates to ensure proper cleanup of network station links.

Technical details

A vulnerability was discovered in the mt76 wireless driver, specifically within the mt7996 module, where the Wireless Connection ID (WCID) pointer was not cleared during the execution of mt7996_mac_sta_deinit_link(). This failure to nullify the pointer when removing a station link can lead to use-after-free scenarios or inconsistent state in the driver's station tracking table. The fix introduces rcu_assign_pointer to properly clear the WCID index before cleanup. The issue affects Linux kernel versions starting from the introduction of the mt7996 station link logic and has been patched in stable branches including 6.18.33 and 7.0.10.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.33, 7.0.10

Timeline

  • 2025-12-05: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats