Impact
During transmission queue management in the rtw88 wifi driver skb() fails to free the socket buffer when an error occurs. This oversight allows a malicious driver invocation to accumulate unreleased memory in the kernel, gradually depleting available memory and impairing overall system performance. The resulting memory exhaustion can ultimately lead to kernel panics or degraded device operation, effectively causing denial of service.
Affected Systems
All Linux kernel releases that contain the rtw88 driver without the recent patch are affected, including distributions that ship a kernel built from mainline sources prior to the implementation of the fix. single vendor or version; any kernel integrating the rtw88 subsystem and executing errant packet pushes may be CVSS score is 4.7, indicating moderate severity. The EPSS score is < exploitation. The vulnerability is not. An attacker would need to trigger the error path within the rtw88 driver, typically through repeated packet transmission failures, to induce the memory leak. Consequently, the risk is moderate and mostly constrained to systems that rely heavily on the rtw88 wireless module.
Risk and Exploitability
The moderate CVSS score of 4.7 indicates medium impact, primarily a memory leak. The EPSS score is less than 1%, which points to a low probability of real‑world exploitation. Since the vulnerability is not in the CISA KEV catalog, there are no known active attacks. An attacker would have to force the rtw_txq_push_skb error path, likely through repeated packet failures, to accumulate memory pressure over time. Systems heavily relying on the rtw88 driver that experience frequent packet errors could suffer gradual memory exhaustion, potentially degrading kernel performance or causing instability.
OpenCVE Enrichment
Debian DSA