Impact
The ath11k Wi‑Fi driver in the Linux kernel contains a flaw that permits a NULL pointer dereference during firmware‑ready handling. When the driver marks firmware as ready even after a failed initialization, a later system‑state‑reset sequence attempts to use uninitialized data structures, causing the kernel to crash. This flaw is an improper handling of state that leads to a kernel panic, which effectively denies service to the host.
Affected Systems
The vulnerability affects the ath11k wireless stack bundled with the Linux kernel. All Linux kernels that include the ath11k driver prior to the inbound patch are impacted. The problem was observed on hardware such as the WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1, but the component is part of the generic kernel, so any distribution shipping the affected kernel may be vulnerable.
Risk and Exploitability
No EPSS score or KEV listing is available, implying limited public exploitation data. The flaw likely requires interaction with the Wi‑Fi interface—such as crafted network traffic or a forced firmware reload—to trigger the faulty firmware‑ready path. While remote code execution is not explicitly described, the resulting kernel crash can serve as a denial‑of‑service vector and potentially open the door for other local attacks. Administrators should treat this as a high‑risk kernel bug until the fix is deployed.
OpenCVE Enrichment