Impact
The vulnerable code exists in the Linux wilc1000 Wi‑Fi driver. When the driver parses a P2P public action frame that is only 25 to 31 bytes long, it fails to verify the frame meets the 32‑byte header length. The code then reads the oui_subtype field out of bounds, and a size underflow causes an over‑sized search buffer that walks into unmapped memory. This results in a kernel panic and a system reboot or loss of service. The weakness is a classic buffer read overflow that can crash the host.
Affected Systems
All Linux kernels that include the wilc1000 driver before the patch commit. The fix addresses the driver in the mainline kernel; any distribution using a pre‑patched kernel is affected. No specific LTS version is singled out, so all up‑to‑date kernels after the patch are safe.
Risk and Exploitability
A nearby unauthenticated wireless device can send a crafted 25‑31 byte P2P action frame to a host in P2P listen mode, triggering the crash. The exploit requires only local wireless proximity and no authentication, making it low effort but potentially high impact for the host. EPSS data is not available and the vulnerability is not listed in the KEV catalog, but the attack scenario is straightforward and the consequences are significant for an affected device.
OpenCVE Enrichment