Executive brief
A vulnerability in the Linux kernel's Libertas Wi-Fi driver could allow a local user to cause a memory leak. This occurs when the system fails to properly release memory during certain initialization errors. Over time, repeated occurrences could exhaust system memory, potentially leading to a system crash or reduced performance.
Technical details
A memory leak vulnerability exists in the Marvell Libertas Wi-Fi driver (drivers/net/wireless/marvell/libertas/cmd.c) within the lbs_allocate_cmd_buffer() function. The root cause is improper error handling in a loop responsible for allocating command buffers; if an allocation for a specific buffer fails, the function exits without freeing previously allocated buffers in the array or the array itself. A local attacker could potentially trigger this failure path to exhaust kernel memory. The issue has been resolved by adding a proper cleanup routine that iterates through the array to free allocated memory before returning an error.
Affected products
- Linux Linux Kernel 2.6.22 to 6.8.2
Timeline
- 2024-05-17: advisory: NVD publication date
- 2024-02-05: patched: Initial fix committed to Linux kernel stable tree
References
- https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9
- https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a
- https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab
- https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186
- https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf
- https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591
- https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3