Impact
The vulnerability stems from the kernel’s Wi‑Fi stack incorrectly handling the length field of the MLE (Management Layer Element) common‑information octet. For certain MLE types the length is not validated, allowing an attacker to craft frames with an oversized or otherwise malformed length field. The kernel can then process data beyond the bounds of the supplied buffer, leading to memory corruption, crashes, or disclosure of kernel memory contents. The impact is primarily loss of integrity and availability, and potentially an escalation vector if code execution can be achieved through the corruption.
Affected Systems
All Linux kernel releases that include the ieee80211 Wi‑Fi driver are potentially affected. The vulnerability is present at the kernel level and therefore applies across all distributions and architectures that ship an unpatched Linux kernel. No specific version range was listed, indicating that any kernel family that has not applied this patch may be vulnerable.
Risk and Exploitability
The vulnerability is kernel‑level, verified to allow memory corruption. The lack of validation for several MLE types permits an attacker to send crafted frames over Wi‑Fi, potentially causing crashes or information leakage. The EPSS score is not available, but local severity is high due to kernel privilege. No KEV listing means it has not yet been observed in the wild; however, the potential impact warrants immediate attention.
OpenCVE Enrichment