Impact
The iwlwifi driver in the Linux kernel uses a loop counter declared as an 8‑bit unsigned integer while the firmware reports the number of program counter entries as a 32‑bit value. When the firmware advertises more than 255 entries, the counter wraps to zero and the loop never terminates, potentially leading to an infinite loop or an out‑of‑bounds read in kernel space. This can cause a kernel panic or a system hang, effectively denying service to the operating system.
Affected Systems
Any Linux system that ships with an iwlwifi driver containing the pre‑fix code is affected. The commit that corrects the counter type was merged into the mainline kernel and is included in recent distribution kernels. Systems running kernel releases older than that commit, or with a custom build that has not applied the change, remain vulnerable. No specific kernel version range was supplied in the CVE data, so the default assessment is that all unpatched kernels are at risk until the fix is applied.
Risk and Exploitability
The EPSS score indicates a less than 1 % chance of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that an attacker would need to trigger the iwlwifi firmware logs that contain an oversized list of program counter entries, which requires either local access or a malicious firmware package supplied by the wireless hardware. No public exploit has been documented, so the overall risk is moderate, but the potential impact merits timely patching to eliminate the possibility of a kernel hang.
OpenCVE Enrichment
Debian DLA
Debian DSA