Impact
The ath12k Wi‑Fi driver in the Linux kernel contains a buffer overflow bug in the mac_phy_caps_parse function. When firmware transmits shorter tables than expected, the driver allocates an array based on a clamped length but later copies data using the full structure size. This causes writes past the end of the allocated buffer, corrupting kernel memory. The vulnerability could be leveraged to crash the system or execute arbitrary code with kernel privileges, as reflected by a high CVSS score. The weakness is a classic buffer overflow (CWE-119/CWE-120).
Affected Systems
All Linux kernel systems that use the ath12k wireless driver are potentially affected. The exact kernel version is not specified, but the defect exists in the code path that parses MAC PHY capability tables. Users running unpatched kernels should evaluate whether their hardware uses the ath12k driver.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation today. The vulnerability is not listed in CISA KEV. Exploitability likely requires an attacker able to send crafted firmware or control packets to the ath12k driver, potentially from a remote Wi‑Fi network. Because the flaw leads to kernel memory corruption, successful exploitation could result in denial of service or privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA