Impact
The vulnerability arises in the ath11k Wi‑Fi driver when the ath11k_service_ready_ext_event() routine allocates mac_phy_caps during parsing of TLVs but fails to free that allocation when a later parsing step fails. The resulting memory leak can gradually consume kernel memory, potentially destabilizing the system or causing a crash. The weakness is an improper resource management flaw, which could be leveraged by an attacker who can inject or influence the TLV stream to provoke the failure path.
Affected Systems
The affected products are Linux kernel builds that include the ath11k Wi‑Fi driver and have not yet incorporated the commit that fixes the memory leak. No specific kernel version range is listed, so all current kernels that use ath11k before the patch are considered vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low probability that the vulnerability will be actively exploited. It is not listed in the CISA KEV catalog. Because the CVE description only mentions parsing of TLVs and leaks on error, it does not explicitly state how an attacker would trigger the failure path; thus the likely attack requires sending crafted Wi‑Fi frames to the ath11k driver, which is inferred from typical Wi‑Fi driver behaviour. The exact vector is not documented in the CVE text, so this inference is based on the driver’s role in processing frames. Without direct privilege escalation, the attack would probably result only in local denial of service, and the overall risk is moderate for systems that rely on ath11k Wi‑Fi connectivity.
OpenCVE Enrichment
Debian DLA
Debian DSA