Impact
The vulnerability in the ath11k wireless driver causes a null pointer dereference in the MHI teardown path while freeing DMA resources, which can bring the entire kernel down during a reboot. This results in a system crash and denial of service as the operating system must be rebooted to recover. The weakness is a classic null pointer dereference exacerbated by a race condition between device shutdown and firmware recovery.
Affected Systems
The issue targets Linux kernel devices that use the ath11k driver on PCI/MHI‑based hardware, such as the WCN6855 hardware revision 2.1 used in WLAN.HSP.1.1 devices. AHB‑based ath11k devices are unaffected and do not queue reset work during SSR flows.
Risk and Exploitability
The risk is significant because a kernel crash leads to system halt until a reboot, and a CVSS score of 8.8 highlights a high severity denial‑of‑service. The EPSS score of < 1% indicates a low exploitation probability, and the lack of a CISA KEV listing suggests it is not yet widely exploited. Nonetheless the potential impact warrants rapid remediation.
OpenCVE Enrichment