Impact
The vulnerability lies in the ath12k Wi‑Fi driver’s handling of the CSA switch count event. Because the driver did not enforce a minimum length on the event structure and used a firmware‑supplied count without validating that it fit within the TLV payload, it could read memory beyond the intended boundaries. This out‑of‑bounds read may expose sensitive data residing in kernel memory if the attacker can trigger the event. The patch adds a TLV policy entry and bounds the loop using the parsed payload length, preventing the overread.
Affected Systems
All Linux kernel installations that use the ath12k wireless driver may be affected. The specific kernel commit series referenced includes commits 878654e and bf97c9d. No particular kernel version range is listed, so any build that incorporates the driver code prior to the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the ability to craft and deliver a malformed WMI event to the target device, which typically entails privileged control over the Wi‑Fi firmware or a managed environment. Because the flaw only allows a read and does not provide code execution or privilege escalation paths, attackers may use it primarily for information gathering rather than direct system compromise.
OpenCVE Enrichment