Executive brief
The MediaTek mt7996 WiFi driver contains a resource leak where transmitted packets' internal tracking tokens are not properly released when certain network configuration lookups fail. An attacker or buggy configuration could repeatedly trigger these failures, exhausting the driver's available tokens and causing WiFi connectivity to degrade or become unavailable.
Technical details
The vulnerability is a resource leak in the mt7996_tx_prepare_skb() function of the MediaTek mt76 WiFi driver. When lookups of link_conf or link_sta structures fail during packet transmission preparation, the function returns early without releasing a previously allocated transmit token. This causes tokens to accumulate as leaked resources. The attack vector is network-reachable; a malformed or specially crafted network configuration or sequence of packets can trigger these lookup failures repeatedly. The fix adds proper token release via mt76_token_release() in an error handling path before returning -EINVAL. Patches were committed to the Linux kernel stable tree starting 2026-05-31.
Affected products
- Linux Linux kernel 5.x, 6.x (prior to patch 831074096d0450308357271fc0ffd3f600a2487e)
Timeline
- 2026-08-15: disclosed: CVE-2026-74323 published
- 2026-05-31: patched: Upstream fix committed by Lorenzo Bianconi (commit 831074096d0450308357271fc0ffd3f600a2487e)
- 2026-07-24: patched: Patch merged into Linux stable trees