Impact
The vulnerability lies in the mwifiex driver in the Linux kernel. It occurs when a synchronous Wi‑Fi command stores a caller‑supplied buffer on the stack and an interrupted wait allows the command to finish after the caller has returned, leaving a dangling pointer. This is a buffer over-read / stale pointer that leads to memory corruption (CWE‑787). A subsequent firmware response writes into this stale buffer, corrupting the kernel stack and causing a panic.
Affected Systems
Any Linux kernel that contains the mwifiex driver and runs Wi‑Fi firmware capable of association/disassociation cycles is affected. The flaw was observed on an i.MX8MP board with an 88W8997 adapter, but the issue exists in all kernels before the recent patch that detaches the caller‑owned buffer when a wait is interrupted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation, and the flaw is not currently listed in the CISA KEV catalog. Exploitation requires an attacker to trigger a Wi‑Fi firmware command that is interrupted on a vulnerable machine, leading to a kernel panic and loss of availability.
OpenCVE Enrichment
Debian DSA