Executive brief
The Linux kernel's MediaTek MT7921 WiFi driver failed to properly clean up allocated resources when device initialization encountered errors during probe. This causes memory and device resource leaks that could degrade system stability or deplete available resources over time if the device fails to initialize repeatedly.
Technical details
A resource leak vulnerability exists in the mt76 driver's mt7921 PCI probe function. When pcim_iomap_region() or devm_kmemdup() fail, the code returns directly without executing cleanup logic, leaving allocated mt76_device and PCI IRQ vector resources unfreed. The fix redirects error paths to the existing error cleanup label (err_free_dev) instead of returning prematurely. This is a code path issue affecting driver initialization; no authentication or network access is required to trigger it—it occurs during device probe. The impact is resource exhaustion, not memory corruption or code execution.
Affected products
- Linux Linux kernel 5.x, 6.x, 7.x and others (mt76 mt7921 driver)
Timeline
- 2026-08-15: disclosed
- 2026-05-12: patched: Fix committed upstream