Impact
The bug resides in the iwlwifi driver of the Linux kernel, where a calculation that allocates fragments for debug TLV structures can produce a divisor of zero. The resulting division-by-zero fault can trigger a kernel panic, causing the operating system to crash and forcing a reboot. This manifests as a denial‑of‑service condition that affects system availability, but does not compromise confidentiality or integrity, and is limited to systems that load the unpatched iwlwifi module.
Affected Systems
All Linux kernel implementations that include the unmodified iwlwifi driver are potentially impacted. The advisory does not enumerate specific kernel versions, so any kernel build lacking the divisor‑zero guard is considered at risk.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires invoking the specific debug path that calls iwl_dbg_tlv_alloc_fragments, which typically demands local privileged access or a scenario where an attacker can influence the size of a debug message. Given these constraints, the overall risk is moderate, though a successful crash would have high impact.
OpenCVE Enrichment
Debian DLA
Debian DSA