Executive brief
A vulnerability in the Linux kernel's Intel Wi-Fi driver can cause a system crash or loss of wireless connectivity. This occurs when the driver attempts to send specific Wi-Fi 6E commands to hardware that does not actually support them, such as the Intel AX201 adapter. An exploit would result in a denial of service, impacting the availability of the affected device.
Technical details
A vulnerability exists in the Linux kernel 'iwlwifi' MVM driver where it fails to properly validate hardware capabilities before sending the MCC_ALLOWED_AP_TYPE_CMD command. While this command is intended for Wi-Fi 6E (UHB) support, certain firmware versions (specifically on AX201 adapters) mistakenly advertise support for it. When the driver issues this command to unsupported hardware, it triggers a firmware crash. The fix introduces an explicit check for 'uhb_supported' in the iwl_mvm_uats_init function to prevent the command from being sent to incompatible devices. This is primarily a local denial-of-service vulnerability.
Affected products
- Linux Linux Kernel All versions prior to the fix in 2026-03-24
Timeline
- 2026-03-24: patched: Initial patch authored by Intel engineers.
- 2026-05-08: disclosed: CVE-2026-43325 published.