Impact
A race condition in the mwifiex driver for Linux kernels causes the driver to incorrectly switch the power‑save state back to awake while a roaming or association operation is still in flight. When this happens, the firmware never sends the expected sleep‑confirm command, leaving scan requests unresolved. Resulting scan operations never complete and any subsequent userspace scan requests fail with an EBUSY error. This leads to a persistent state where Wi‑Fi scans cannot finish, effectively denying the device from discovering or connecting to other networks until a reset or new firmware is loaded.
Affected Systems
The vulnerability affects any Linux kernel build that includes the mwifiex Wi‑Fi driver, particularly on devices using Intel wireless firmware such as the IW412 and W8997 modules. No specific kernel version is listed, so the issue could be present in any kernel revision before the fix was merged into the mainline tree.
Risk and Exploitability
No CVSS score is provided and the EPSS score is unavailable; the vulnerability is not in the CISA KEV catalog. The attack surface appears to be local or remotely triggered via crafted roaming or association sequences. While the fault can cause a denial of Wi‑Fi scanning on the affected host, it does not provide remote code execution or privilege escalation, and no widespread exploitation has been reported. The risk is therefore moderate, limited to device availability and user experience rather than broader network compromise.
OpenCVE Enrichment