Impact
The vulnerability is a use‑after‑free bug in the Linux mwifiex wireless driver. While parsing A‑MSDU TDLS frames, the driver incorrectly supplies the parent packet length instead of the actual subframe length. This mis‑calculated length can cause the code to read freed memory or read beyond the end of a buffer, which may lead to a denial of service or, if an attacker can control the data, possible code execution.
Affected Systems
All systems running the Linux kernel with the mwifiex driver enabled for Wi‑Fi hardware that supports TDLS. The vendor is Linux, and the driver is part of the kernel’s wireless stack. No specific kernel version is listed, so any installation of Linux that includes this driver and has TDLS support active is potentially affected.
Risk and Exploitability
Based on the description, the likely attack vector is remote via TDLS frames transmitted over the wireless interface. Successful exploitation requires that the target’s firmware supports TDLS and that the driver is active. The CVSS score is 8.8, indicating a high severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation at the time of the advisory. Nonetheless, attackers could trigger the bug by manipulating subframe lengths, making the risk significant for exposed wireless devices.
OpenCVE Enrichment
Debian DSA