Impact
The vulnerability occurs in the nl80211 Wi‑Fi subsystem of the Linux kernel, where nl80211_color_change() allocates beacon_next attributes through nl80211_parse_beacon(). A parsing failure returns immediately instead of executing the out: cleanup block, leaving previously allocated memory unreleased. This memory leak can, over time, consume kernel memory and cause a denial of service. The weakness corresponds to missing resource cleanup or release, as captured by CWE-404 and CWE-775.
Affected Systems
All Linux kernel installations that include the nl80211 Wi‑Fi driver are affected, regardless of distribution. The vulnerability is present in the kernel source itself, with no specific product version listed, so any pre‑patched kernel remains vulnerable.
Risk and Exploitability
The EPSS score is reported as <1 %, and the issue is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The attack vector is most likely local, involving an application that sends malformed netlink messages to the nl80211 interface, or potentially remotely via a compromised wireless interface. The impact is resource exhaustion leading to kernel instability or a crash. Despite the low exploitation likelihood, the irreversible nature of kernel memory leaks warrants prompt remediation.
OpenCVE Enrichment