CVE-2021-47030: mt76: mt7615: fix memory leak in mt7615_coredump_work
In the Linux kernel, the following vulnerability has been resolved:
mt76: mt7615: fix memory leak in mt7615_coredump_work
Similar to the issue fixed in mt7921_coredump_work, fix a possible memory
leak in mt7615_coredump_work routine.
Security readout for executives and security teams
Plain-English summary
CVE-2021-47030 is a Linux kernel issue in the MediaTek mt76/mt7615 wireless driver. The coredump work routine could leak memory. The public record does not provide CVSS, active exploitation evidence, or a detailed impact statement, so urgency depends on whether affected kernels and this driver are present.
Executive priority
Handle through routine kernel patch management, with higher priority for laptops, appliances, or embedded systems using MediaTek mt7615 wireless hardware. Current public evidence does not support emergency escalation.
Technical view
The Linux kernel fix addresses a possible memory leak in mt7615_coredump_work, similar to a prior mt7921 coredump issue. The source bundle identifies affected Linux 5.12-era versions and stable kernel commits as references, but does not document trigger conditions, privilege requirements, or exploitability.
Likely exposure
Exposure appears limited to systems running affected Linux kernel versions with the mt76 mt7615 wireless driver path present. Servers without this hardware or driver are less likely to be exposed, based on the available description.
Exploitation context
The provided sources do not show CISA KEV listing, active exploitation, public exploit details, or weaponized use. Treat this as a kernel maintenance issue unless local evidence shows affected wireless driver use on important systems.
Researcher notes
Evidence is sparse: no CVSS, CWE, detailed affected matrix, or exploitation analysis is provided. The strongest source-grounded conclusion is a fixed Linux kernel memory leak in mt7615 coredump handling, with exposure tied to driver and kernel presence.
Mitigation direction
Update affected Linux kernels through the normal vendor or distribution channel.
Prioritize systems using MediaTek mt7615 or mt76 wireless functionality.
Check whether vendor kernel builds include the referenced stable fixes.
Monitor Linux distribution advisories for backported fixes and package availability.
Validation and detection
Inventory kernel versions against the affected 5.12-era range in the CVE record.
Identify hosts loading or shipping the mt76 mt7615 driver.
Confirm installed kernel source or changelog includes the referenced stable commits.
Review system monitoring for abnormal memory growth on affected wireless systems.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47030 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.