Executive brief
The Linux kernel's MT7996 WiFi driver contains an out-of-bounds array access vulnerability in its packet transmission function. When the WiFi stack does not specify which link to use, the driver attempts to use an uninitialized link identifier (0xf) to index into arrays that only have 15 entries, potentially causing memory corruption or denial of service.
Technical details
The vulnerability is an out-of-bounds array access in the mt7996_tx() function of the MediaTek MT7996 WiFi driver. When mac80211 leaves the link unspecified, the driver substitutes the primary link ID, which holds the value IEEE80211_LINK_UNSPECIFIED (0xf) until the first link is added. This invalid value is then used unchecked to index vif->link_conf[], mvif->mt76.link[], and sta->link[], all of which are sized for IEEE80211_MLD_MAX_NUM_LINKS (15) entries. The fix clamps the primary link ID to the default link (0) before use to prevent the out-of-bounds access. The vulnerability affects local kernel code paths and requires no network access or user interaction.
Affected products
- Linux Linux kernel affected versions with mt76 mt7996 driver prior to commit 4330a0ef9f75a54fde3548432a9a698f06bab635
Timeline
- 2026-09-17: disclosed
- 2026-08-01: patched: patch commit 4330a0ef9f75a54fde3548432a9a698f06bab635