Impact
In the Linux kernel, the mac80211_hwsim module can drop a NULL skb object during a stop queue drain. A race between the queueing logic and transmit status handling permits a frame to be removed after an emptiness check but before the dequeue operation, causing ieee80211_free_txskb to receive a null pointer. The null deallocation results in a kernel crash, leading to a denial of service for the affected system.
Affected Systems
All Linux kernel builds that include the mac80211_hwsim wireless simulator, which is present in the mainline kernel, are potentially affected. No specific version range is listed, so the vulnerability applies to all releases until the patch is applied.
Risk and Exploitability
The vulnerability can crash the kernel, causing a denial of service. The EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog, meaning no publicly documented exploitation yet. Based on the description, the attack would likely be limited to a local race condition within the mac80211_hwsim module; an attacker would need to trigger transmission events that interact with the driver to force the race, so reaching the vulnerable state requires relatively rudimentary interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA