Impact
A logic flaw in the rtw89 Wi‑Fi driver of the Linux kernel mishandles malformed AMPDU frames. When the first AMPDU packet arrives with a particular sequence‑number range during a rekey operation, the driver’s state‑reset logic fails, causing unintended packet drops that lead to an abrupt disconnection from the wireless access point. The weakness stems from an improper reset scenario (CWE‑841).
Affected Systems
All Linux kernel builds that include the rtw89 driver are potentially affected. The vendor is Linux and the product is the Linux kernel; no specific kernel version numbers are reported, so any deployment of the kernel with this module could be impacted.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV, indicating a low probability of widespread exploitation. An attacker with local wireless access could transmit crafted AMPDU frames during periods of busy traffic or while a rekey is in progress to trigger the flaw. Exploitation would result in a denial‑of‑service state via Wi‑Fi disconnection rather than code execution or data compromise, and the moderate severity suggests prompt patching in environments that rely on continuous wireless connectivity.
OpenCVE Enrichment