<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Mt76 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mt76/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 10:08:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mt76/feed.xml" rel="self" type="application/rss+xml"/><item><title>NULL Pointer Dereference Vulnerability in MediaTek mt76 Wi-Fi Driver</title><link>https://feed.craftedsignal.io/briefs/2026-08-mt76-null-ptr/</link><pubDate>Tue, 11 Aug 2026 10:08:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-mt76-null-ptr/</guid><description>A NULL pointer dereference vulnerability exists in the MediaTek mt76 driver within the mt76_connac_mcu_uni_bss_he_tlv function, potentially leading to kernel panic or denial-of-service conditions.</description><content:encoded><![CDATA[<p>CVE-2026-68309 identifies a security vulnerability within the mt76 kernel driver used for MediaTek Wi-Fi chipsets. The issue is located in the <code>mt76_connac_mcu_uni_bss_he_tlv()</code> function. A lack of proper validation when processing BSS HE (High Efficiency) TLV data structures can lead to a NULL pointer dereference. This flaw is triggered during the processing of wireless management frames or specific hardware communication packets. If exploited, an attacker capable of sending specially crafted frames to the affected wireless interface could cause the kernel to crash, resulting in a system denial-of-service. This vulnerability primarily affects devices utilizing the MediaTek mt76 driver stack, which is commonly found in Linux-based wireless network hardware.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in kernel instability, typically manifesting as a system crash or hang. This denial-of-service condition affects the availability of the network interface and the host system. As the driver operates within the kernel space, this flaw poses a risk to devices ranging from embedded Wi-Fi access points to laptops and IoT devices relying on MediaTek chipsets for wireless connectivity.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch the Linux kernel or firmware associated with MediaTek mt76 drivers to the version addressing CVE-2026-68309.</li>
<li>Implement kernel hardening measures, such as enabling PAN (Privileged Access Never) or SMAP (Supervisor Mode Access Prevention), to mitigate the impact of kernel-level pointer dereference vulnerabilities.</li>
<li>Monitor system logs for kernel oops or panic messages specifically referencing the mt76 driver during periods of high wireless traffic.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>denial-of-service</category><category>kernel</category><category>firmware</category><category>informational</category><category>product-news</category><category>linux</category></item></channel></rss>