Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ath11k wireless driver has been addressed, which involved improper error handling in certain Wake on Wireless (WoW) commands. The issue arose because the return value of a command sending function was not checked, leading to a failure to free a buffer in case of an error. This vulnerability affects the Linux kernel stable tree.
The vulnerability could lead to memory management issues, specifically buffer leaks, which may be exploited to cause unintended behavior in the system.
The vulnerability can be reproduced by invoking the WMI WoW host wakeup indication command or the WMI WoW enable command in the ath11k driver. These commands can be sent without proper error handling, allowing the vulnerability to manifest.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.