Impact
The rtw89 wireless driver in the Linux kernel accepts an 8‑bit MAC identifier from firmware without validating it before using it as an index into an internal array that has only 128 entries. If an out‑of‑range value is provided, the driver will access memory beyond the array bounds, causing kernel memory corruption and potentially a system crash or reboot, thereby delivering a denial‑of‑service condition.
Affected Systems
The vulnerability resides in the Linux kernel’s rtw89 wireless driver. Any Linux distribution shipping an unpatched kernel with this driver is potentially affected. Systems that load the rtw89 driver and accept firmware updates from external sources must consider this risk.
Risk and Exploitability
The CVSS score of 8.8 places the flaw in the high‑severity range, while the EPSS of <1% suggests a very low exploitation probability. Based on the description, it is inferred that the attack would require the attacker to supply a malicious firmware image to the driver; the likely attack vector is through firmware update mechanisms. Because of this limited exposure, the vulnerability is not listed in the CISA KEV registry, indicating no known widespread exploitation.
OpenCVE Enrichment