Impact
The Linux kernel wireless driver iwlwifi contained a flaw that does not verify the length of a Service Access Point (SAP) message before copying it into a local buffer. An attacker that can inject an oversized SAP message will cause the kernel copy operation to overflow the buffer, allowing the attacker to overwrite adjacent kernel memory. Depending on the memory layout, this overflow could be used to execute arbitrary code, elevate privileges, or crash the kernel, resulting in a denial‑of‑service. The CVSS score of 8.4 indicates that code execution is a realistic outcome.
Affected Systems
All Linux systems running a kernel that contains the iwlwifi driver and the MEI interface, regardless of distribution, are potentially affected. No explicit version ranges were provided, but any kernel revision prior to the patch that added the SAP message length check is vulnerable.
Risk and Exploitability
With a CVSS score of 8.4 the vulnerability is high severity. The EPSS score of less than 1% indicates that, at the time of analysis, the probability of a publicly available exploit is very low. The vulnerability is not listed in the CISA KEV catalog, so it is not known to be actively exploited in the wild. The likely attack vector involves an attacker sending crafted SAP messages over the wireless interface to the target device, which requires the device to be in a state where the iwlwifi driver processes these messages. Local exploitation is possible, and if the attacker gains higher privileges, remote code execution across the host can be achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA