Impact
The Linux kernel’s mac80211 stack misinterprets a missing CSA channel value as zero, a value that is not a valid channel. When an access point advertises a switch to channel zero, the kernel fails to disconnect as it should, and on Intel wireless devices this misinterpretation can trigger a firmware crash. The vulnerability does not provide direct code‑execution or data‑exfiltration capabilities, but it can render the device non‑functional or force it to reboot, disrupting connectivity instead.
Affected Systems
All Linux kernel distributions that include the mac80211 wireless subsystem are potentially affected, with the most direct impact on Intel‑based Wi‑Fi hardware. No specific kernel release or version was enumerated in the advisory, so any kernel that has not incorporated the patch may be vulnerable.
Risk and Exploitability
The escalation is limited to a local or remote attacker that can control or spoof an access point. Because the issue requires a malformed CSA to be broadcast, normal user traffic does not trigger it. EPSS is reported as <1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. However, the severity of a firmware reboot can be high for critical infrastructure. The risk remains moderate, with exploitation feasible in environments where wireless traffic can be monitored or injected by an attacker.
OpenCVE Enrichment
Debian DLA
Debian DSA