Impact
In the Linux kernel ath11k Wi‑Fi driver, a buffer intended to hold MAC PHY capability data is allocated with a size based on an incorrect stride calculation. When firmware transmits shorter-than‑expected TLVs, the subsequent memcpy writes past the end of the allocated buffer. This results in a heap overflow that corrupts kernel memory and could enable an attacker to overwrite critical kernel structures, potentially leading to arbitrary code execution at kernel privilege level. The weakness is a classic heap‑based buffer overflow.
Affected Systems
All Linux installations that include the ath11k driver and have not applied the patch. The affected code resides in the Linux kernel, specifically in the ath11k module. Any system using a kernel version that contains the vulnerable buffer allocation logic and receives firmware that can supply malformed TLVs is at risk.
Risk and Exploitability
The CVSS score of 8.4 classifies this as high severity. The EPSS score of <1% indicates low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. However, exploitation would require an attacker who can influence the Wi‑Fi firmware or craft malicious TLVs, typically via a local network or compromised device. The impact, if achieved, would be catastrophic kernel compromise. Given the low exploitation probability but high consequence, timely patching is advised.
OpenCVE Enrichment
Debian DLA
Debian DSA