Impact
This flaw allows a remote attacker to trigger an out‑of‑bounds read in the Linux kernel’s WiFi subsystem by sending a malicious beacon that contains a truncated EHT Multi‑Link Element (MLE). The kernel code incorrectly assumes the MLE is a standard BASIC form, validating only length before accessing its fields. The resulting memory read can expose sensitive data or trigger a crash, undermining confidentiality or availability, but does not provide direct code execution.
Affected Systems
All Linux kernels containing the cfg80211 WiFi stack before the patch are affected, regardless of vendor distribution. No specific version range is listed.
Risk and Exploitability
The vulnerability has no publicly disclosed CVSS score but has an EPSS score of less than 1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. Attackers would need to position a rogue access point within radio range, making the damage confined to devices in the same WiFi environment. The exploit path relies purely on the victim’s WiFi receiver parsing the beacon, so no additional host privileges are required.
OpenCVE Enrichment