Impact
A bug in the Linux kernel’s wireless driver wlcore causes a runtime power‑management reference to be released only on success, while the failure path retains the reference after scheduling recovery. If an attacker triggers the failure path repeatedly, the reference count can become unsynchronized, potentially leading to a use‑after‑free situation and a kernel crash. The primary impact is a denial of service by destabilizing the operating system, rather than leaking data or elevating privileges.
Affected Systems
All Linux kernel builds that include wlcore without the patch are affected. The exact kernel versions are not specified in the advisory, so any distribution using the stock kernel should assess whether the wlcore driver is present and unpatched.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, making the likelihood of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely a local or remote user able to send malicious regulatory‑domain commands to a wireless interface, as the bug is triggered during wlcore_regdomain_config_locked processing. Because the defect involves kernel reference counting, successful exploitation would require privilege escalation or local access to the wireless interface.
OpenCVE Enrichment