Impact
The ath11k wireless driver releases tx_status buffers during a firmware initialization failure and releases them again upon device removal. This double free triggers a SLUB allocator warning in the kernel logs and may lead to undefined kernel behavior, but no crash is confirmed in the provided description.
Affected Systems
All Linux kernel releases that include the ath11k driver prior to the patch that nulls buffer pointers after release are affected. The issue exists in vendor builds of the kernel containing the unpatched ath11k code.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk. The EPSS score of less than 1% suggests a very low probability of exploitation. Exploitation requires a firmware initialization failure that can be induced locally or via kernel-level access, so the attack vector is likely local. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA