Impact
The iwlwifi driver in the Linux kernel mistakenly sends a 6E capability command (MCC_ALLOWED_AP_TYPE_CMD) even when the underlying firmware does not advertise support for 6E. This incorrect command invocation causes the firmware to crash, disabling the wireless subsystem and interrupting network connectivity. The flaw lies in the driver’s lack of validation for the firmware’s advertised capabilities.
Affected Systems
Linux systems running a kernel version before the patch that contains this iwlwifi driver bug, using Intel wireless adapters that do not support 6E, including the AX201 device referenced in the description. Any distribution shipping the affected kernel will be vulnerable until updated.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate impact, and the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The flaw causes a firmware crash when the driver sends an unsupported 6E capability command, likely requiring local access or routine operation of the wireless device. The impact is a denial‑of‑service for wireless connectivity.
OpenCVE Enrichment