Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A NULL pointer dereference vulnerability has been identified in the Linux kernel's ath11k wireless driver for the IPQ5018 chipset. This issue arises because the hardware operations structure for IPQ5018 does not properly initialize the ring selector function. As a result, when data is transmitted after clients connect, the driver attempts to call a function that hasn't been set, leading to a kernel crash. The vulnerability manifests as a stack trace indicating a failure to handle a NULL pointer dereference, with the process 'hostapd' involved.
Exploitation of this vulnerability causes a kernel panic due to a NULL pointer dereference, disrupting all processes and services running on the device.
The vulnerability can be reproduced by connecting clients to a device using the IPQ5018 chipset that is running the affected version of the Linux kernel. Once connected, the device will attempt to send data, triggering the NULL pointer dereference in the ath11k driver.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.