Impact
A flaw in the ath6kl Wi‑Fi driver allows firmware to specify a message length greater than the actual buffer size, causing the driver to read beyond the end of the buffer during a TX complete event. This out‑of‑bounds read is limited to at most 1020 bytes and may expose kernel memory contents to an attacker, but it does not provide arbitrary code execution. The weakness is manifested as improper validation of firmware‑controlled data, a classic input‑validation error. The attack would leak internal driver or kernel state that could assist a local attacker in further compromising the system or in escalating privileges.
Affected Systems
The issue affects the Linux kernel firmware driver for ath6kl Wi‑Fi chips. No specific kernel release numbers are listed in the vulnerability data, so any Linux kernel that includes the ath6kl module prior to the fix is potentially affected. The vendor derived from the CNA is Linux, and the product is the Linux kernel itself.
Risk and Exploitability
Overall, the vulnerability is a local kernel out‑of‑bounds read that could leak sensitive data, with a CVSS score of 8.1 indicating high severity. It is not currently exploited in the wild, and the exploitation requires interaction with the Wi‑Fi firmware. The EPSS score of <1% suggests a low probability of exploitation at present. Nonetheless, any system that processes untrusted firmware packets through the ath6kl driver should treat it as a serious information‑disclosure risk until patched.
OpenCVE Enrichment
Debian DLA