Impact
The vulnerability in the Linux kernel’s iwlwifi driver allows the last byte of a Wi‑Fi key to remain unsanitised during memory cleanup. This off‑by‑one error means that one byte of a key may remain in memory, potentially enabling a local attacker to read a part of the key and compromise the confidentiality of wireless traffic. The impact is limited to a single key byte but could be compounded if several keys are affected or if keys are long enough to provide sufficient material for cryptanalysis.
Affected Systems
All Linux systems that use the iwlwifi driver in the kernel, regardless of distribution. The affected code path is part of the kernel’s wireless interface module for Intel wireless devices. Specific kernel versions are not listed; any version prior to the patch should be considered vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not included in CISA’s KEV catalog, indicating a low probability of successful exploitation. However, the CWEs associated with buffer calculation errors and information disclosure suggest that if an attacker gains local kernel execution or can observe memory, a single key byte could be recovered. The risk is therefore moderate: significant but difficult to exploit, and mitigated by updating to a kernel version where the bug is fixed.
OpenCVE Enrichment
Debian DLA
Debian DSA