Linux Kernel Wi-Fi MT76 WCID Publication Check Vulnerability

Vulnerability

A vulnerability in the Linux kernel's Wi-Fi MT76 driver can lead to a use-after-free condition. This issue arises because the MT7925 MAC station addition function publishes the Wireless Context Identifier (WCID) without proper checks, causing corruption in the station polling list. The vulnerability was introduced in the Linux 7.1 release candidate 4 and affects the stable Linux kernel.

Impact

Exploitation of this vulnerability can cause memory corruption, leading to a use-after-free condition. This type of vulnerability can often be exploited to execute arbitrary code or cause a denial-of-service condition by crashing the system.

Reproduction

The vulnerability can be reproduced by using a device with a MediaTek MT7925 Wi-Fi chip and connecting to a wireless access point. The MT7925 MAC station addition function will publish the WCID, which can then be improperly handled by the MT76 driver, causing corruption in the station polling list.

Remediation

Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed.

Added: Jul 19, 2026, 12:24 PM
Updated: Jul 19, 2026, 12:24 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.