No Password, No Association, No Fix: Four Bugs in the Wi-Fi Daemon SteamOS Ships by Default
A nearby attacker can knock a Linux machine off Wi-Fi with one spoofed frame — no password, no association. iwd writes 31 bytes per visible access point into a 512-byte stack buffer and never checks; seventeen APs in range overflows it. SteamOS ships iwd as its default backend, where the impact is a crash rather than code execution. Reported in May, confirmed, patches sent. Still unfixed.