Impact
During a reboot on arm64 platforms, the rtw89 PCI wireless driver lacks a .shutdown callback. Askill polling work continues while the PCIe link is torn down, leading to asynchronous SError errors that trigger a kernel panic. The primary impact is a complete system halt, effectively a denial of service. This flaw is a classic case of improper cleanup of hardware resources, corresponding to CWE-772.
Affected Systems
The vulnerability applies to Linux kernel builds that include the rtw89 PCI driver on arm64 platforms. Specific kernel versions are not listed, so the affected range remains unspecified. Users of this driver should review the changelog for the update that kernel build contains the RTW89_FLAG_SHUTDOWN flag and the shutdown callback.
Risk and Exploitability
The flaw is triggered by any normal shutdown sequence invoking device_shutdown. Because the vulnerability activates only during the local shutdown process, remote attack is not possible. The EPSS score is < 1%, indicating a low exploitation probability, but the CVSS score of 4.7 reflects a moderate technical severity. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits exist. Until a kernel update or patch is applied, the risk is considered medium‑to‑high given the potential for system-wide interruption.
OpenCVE Enrichment