Impact
The flaw triggers when the ath12k Wi‑Fi driver reads a firmware buffer without first confirming that the buffer contains at least the size required for a wmi_cmd_hdr. This unchecked bounds check can cause a buffer overread, potentially allowing the driver to read unintended memory locations and crash the kernel. The vulnerability does not expose additional network traffic or channels beyond this memory access.
Affected Systems
Linux kernel builds that include the ath12k driver, particularly those running Qualcomm Atheros hardware such as the WCN7850. No specific kernel version is enumerated, so any kernel containing a vulnerable ath12k module may be affected.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation at this time. No public exploits are documented. Exploitation would likely require an attacker to supply malicious firmware or otherwise influence the driver’s communication with the device, which generally requires local or privileged access. The potential impact is limited to kernel crashes or unintended memory reads; the overall risk remains low unless a targeted exploit is discovered.
OpenCVE Enrichment
Debian DLA
Debian DSA