wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
mt76_connac_get_eht_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/2b1882cf313ae44181146629b3578a7826c672c9https://git.kernel.org/stable/c/2fffc472bec490c8357defcee9c075ca74467352https://git.kernel.org/stable/c/3e4f848f4a620e1d77c38459e73cf3b362f7bc6bhttps://git.kernel.org/stable/c/45c496756c6f6df6c3aeb5b2cb996993d2f14687https://git.kernel.org/stable/c/d5628f39fccc107dca00b98a491d9848898599f7