Junglewise Threat Intelligence

CVE-2026-74322: Linux kernel mt76 mt7996 NULL pointer dereference in mac write

CVE-2026-74322 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A wireless driver component in the Linux kernel can crash due to a null pointer dereference when processing injected wireless frames (e.g., via packet injection tools). An attacker with local access to inject frames could trigger a kernel panic, causing wireless service disruption or system crash.

Technical details

A NULL pointer dereference vulnerability exists in the mt7996_mac_write_txwi_80211() function within the MediaTek mt76 wireless driver. The function fails to check whether the Virtual Interface (vif) pointer is NULL before calling ieee80211_vif_is_mld(), but mac80211 explicitly allows vif to be NULL for injected frames (e.g., radiotap). The vulnerable code path is triggered when processing multicast frames or null function frames with injected frame control structures. An attacker with local network access and the ability to inject wireless frames can trigger the NULL pointer dereference, causing a kernel panic. The patch adds a NULL check on the vif pointer before all calls to ieee80211_vif_is_mld().

Affected products

  • Linux Linux kernel versions including mt76 mt7996 driver with MLO support (fixed in commit 61370e6674b5253de5686813ceeceebc35a7d3e5)

Timeline

  • 2026-08-15: disclosed
  • 2026-05-31: patched: fix committed upstream

References

Related threats