Impact
A flaw in the Linux kernel wlcore driver causes the firmware to progressively reduce the number of enabled cryptographic ciphers on each boot when the firmware is older than expected. The driver fails to set keys correctly, which triggers the hardware to restart repeatedly and prevents normal wireless operation. As a result, any device using an affected wl12xx Wi‑Fi chip will experience persistent connectivity loss or a complete service interruption.
Affected Systems
The issue involves the Linux kernel and the wlcore wireless driver for wl12xx chips running firmware revision 7.3.10.0.142 and earlier. Systems running newer firmware or non‑wl12xx devices are not affected; only Linux installations that use the wlcore driver with older firmware encounter the problem.
Risk and Exploitability
The vulnerability is local to the device; an attacker would need physical access or be able to influence the device firmware. Because the exploit triggers only after a reboot or when the driver loads, it is not directly reachable from remote code execution. The likelihood of exploitation in the wild is low, and the vulnerability is not currently listed in the CISA KEV catalog and lacks an EPSS score. However, the impact remains significant for affected devices due to recurring hardware restarts and denial of Wi‑Fi service.
OpenCVE Enrichment