Impact
The ath6kl driver for Wi‑Fi hardware in the Linux kernel contains functions that read event data from the WMI buffer without checking that the data is long enough. When a message is smaller than expected, the driver overreads kernel memory. Depending on how the attacker can supply WMI messages, this could leak confidential data or trigger a crash, impacting confidentiality and availability.
Affected Systems
This flaw affects all Linux systems whose kernel includes the ath6kl wireless driver. No specific kernel releases are listed, so every distribution that ships the driver in the kernel is potentially affected until the patch is applied.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The bug resides in kernel‑space code, so an attacker would need the ability to send crafted WMI messages to the ath6kl device, which may require privileged firmware access or physical proximity. The CVSS score is not provided, but the lack of external exploitation data and the local nature of the vulnerability suggest a moderate risk if an attacker can meet the prerequisites.
OpenCVE Enrichment
Debian DLA
Debian DSA