Impact
The vulnerability resides in the Linux wireless driver ath10k, where the firmware crash‑dump routine copies the MSA memory region using the generic memcpy function. On arm64 platforms, this memory tier is mapped with devm_memremap(MEMREMAP_WT) and is not normal‑cacheable, meaning unaligned accesses are prohibited. The generic memcpy implementation performs wide, unaligned loads. When this code path is executed, an alignment fault (FSC=0x21) is raised, causing an Oops that crashes the kernel and leaves the firmware RAM dump buffer empty, thereby breaking modem self‑recovery.
Affected Systems
This defect impacts Linux kernels that include the ath10k driver before the patch that replaces memcpy with memcpy_fromio. The bug is specifically relevant to the WCN3990/SNOC WLAN hardware on arm64 machines, as demonstrated in the test environment identified in the advisory. No explicit version range is provided, so any kernel release incorporating the original code path is considered vulnerable until the commit that introduces memcpy_fromio is merged.
Risk and Exploitability
The EPSS score for this CVE is below 1 %, and it is not listed in the CISA KEV catalog, suggesting a low probability of public exploitation at present. However, the bug can cause a kernel crash and denial of service in affected systems; the damage is local but can lead to a loss of modem functionality if the crash occurs during a firmware failure. Because the trigger is the crash‑dump routine, an attacker would need to provoke a firmware crash or manipulate driver behaviour, which may be feasible if firmware can be controlled or via privileged local access.
OpenCVE Enrichment
Debian DLA
Debian DSA