Impact
The kernel driver for ath11k wireless chipsets has an unchecked loop bound that allows an arbitrary out-of-bounds read of kernel memory. The number of virtual devices reported by firmware is used directly as a bound on an array without verifying it fits within the received data, which can cause the kernel to read beyond the intended buffer and expose kernel memory contents.
Affected Systems
Linux systems that load the ath11k driver are potentially affected. Based on the description, it is inferred that Qualcomm Atheros QCA99x0 or similar 802.11ac/802.11ax wireless hardware could be the target. Any kernel build including the ath11k driver before the patch that adds a TLV policy entry and bounds size validation is potentially affected.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. The EPSS score of less than 1 % suggests a very low likelihood of active exploitation at this time. The vulnerability is not listed in CISA KEV. An attacker would need to influence the driver to process a crafted WMI event, which typically requires local or privileged access, making remote exploitation unlikely without additional conditions.
OpenCVE Enrichment
Debian DLA
Debian DSA