Impact
The kernel Wi‑Fi driver for ath12k contains a use‑after‑free bug that occurs when tearing down an AP virtual interface. After a failed peer creation, the driver does not unassign the dp_link_peer before freeing it, leaving dangling pointers in several kernel data structures. This can lead to kernel memory corruption that an attacker can exploit to elevate privileges or crash the system.
Affected Systems
The flaw is confined to the Linux kernel’s ath12k Wi‑Fi driver. It affects any Linux distribution that ships with a kernel version containing that driver, regardless of the specific kernel release, as no version range is supplied in the advisory.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV, indicating very low observed exploitation probability. The CVSS score is not provided, but the lack of public exploitation and the requirement for kernel interaction suggest the attack vector is local. No workarounds are available, so the safest approach is to apply the official patch as soon as possible.
OpenCVE Enrichment