{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63866","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.017Z","datePublished":"2026-07-19T14:04:51.806Z","dateUpdated":"2026-08-05T12:36:42.414Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:36:42.414Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()\n\nClear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link\nroutine."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The bug is in the MediaTek mt7996 WiFi driver and is reached when MLO station links are torn down via mac80211's change_sta_links callback, which a remote WiFi peer can trigger through 802.11be MLO association/reconfiguration (malicious AP to a client, or a malicious associated client to an AP/router).\nAC:L - An attacker who can complete or maintain an MLO WiFi session can deterministically trigger link removal/reconfiguration to hit mt7996_mac_sta_deinit_link(); no special memory layout or victim timing is required beyond normal MLO link churn the attacker controls.\nPR:N - Exploitation requires no local OS privileges on the victim; the attacker only needs to act as a WiFi peer (e.g., malicious AP or associated MLO client) to drive mac80211 link changes into the driver, not root/CAP_NET_ADMIN on the target host.\nUI:N - No victim user action beyond normal automatic WiFi operation is required; link add/remove is driven by the attacker's 802.11 MLO signaling once the victim device is operating as a WiFi client or AP with MLO enabled.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel/host security boundary; this is not a VM escape, sandbox escape, or cross-authority boundary bypass.\nC:H - Failing to NULL the global dev->mt76.wcid[idx] entry before mt76_wcid_mask_clear() and kfree_rcu() leaves a use-after-free; stale wcid pointers are dereferenced on RX/TX completion paths via mt76_wcid_ptr(), enabling arbitrary kernel memory reads.\nI:H - The dangling wcid pointer permits writes through subsequent TX/RX and wcid-based container_of lookups on freed mt7996_sta_link objects, giving attacker-influenced heap corruption primitives suitable for control-flow hijacking.\nA:H - Use of a freed wcid structure during packet TX completion or RX processing can cause kernel oops/panic or wedged WiFi subsystem, and UAF corruption alone satisfies High availability impact even before full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/mt7996/main.c"],"versions":[{"version":"dd82a9e02c054052b5899872c1f32805428f6131","lessThan":"455a48685feebf2d9c1656caad77f9ba1da7b06e","status":"affected","versionType":"git"},{"version":"dd82a9e02c054052b5899872c1f32805428f6131","lessThan":"c575459b485c47615491b1fd29f04b43fdc3da56","status":"affected","versionType":"git"},{"version":"dd82a9e02c054052b5899872c1f32805428f6131","lessThan":"88973240dc7c976dd320b36a9e6d925c9be083ae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/mt7996/main.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/455a48685feebf2d9c1656caad77f9ba1da7b06e"},{"url":"https://git.kernel.org/stable/c/c575459b485c47615491b1fd29f04b43fdc3da56"},{"url":"https://git.kernel.org/stable/c/88973240dc7c976dd320b36a9e6d925c9be083ae"}],"title":"wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()","x_generator":{"engine":"bippy-1.2.0"}}}}