Impact
This vulnerability stems from an off‑by‑one error in the Linux wireless driver rtw89, where a comparison should use >= instead of >, allowing a buffer index to exceed the bounds of an array during debug string generation. The faulty logic can lead to a memory read or write outside the intended bounds, potentially corrupting data, leaking information, or causing a crash. The impact is limited to memory corruption rather than escalation of privileges, but could still disrupt device stability or expose sensitive data within the kernel context.
Affected Systems
All Linux installations that include the rtw89 wireless driver may be affected, regardless of specific version, unless the patch has already been incorporated into the kernel. Specific affected releases are not enumerated in the available data.
Risk and Exploitability
The vulnerability is listed with an EPSS score of less than 1%, indicating a very low likelihood of exploitation, and it is not cataloged in CISA KEV. Because the flaw exists in a debug routine, an attacker would likely require local access or elevated privileges to exercise the vulnerable code path, reducing practical risk. Nonetheless, the out-of-bounds access could lead to kernel crashes or data leakage if triggered, so assessment of whether the driver is active or debug logging is enabled is prudent.
OpenCVE Enrichment