Junglewise Threat Intelligence

CVE-2024-35828: Linux Kernel Libertas Wi-Fi driver memory leak in lbs_allocate_cmd_buffer

CVE-2024-35828 · Severity: medium · CVSS 5.5 · Published 2024-05-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Libertas Wi-Fi driver could allow a local user to cause a memory leak. This occurs when the system fails to properly release memory during certain initialization errors. Over time, repeated occurrences could exhaust system memory, potentially leading to a system crash or reduced performance.

Technical details

A memory leak vulnerability exists in the Marvell Libertas Wi-Fi driver (drivers/net/wireless/marvell/libertas/cmd.c) within the lbs_allocate_cmd_buffer() function. The root cause is improper error handling in a loop responsible for allocating command buffers; if an allocation for a specific buffer fails, the function exits without freeing previously allocated buffers in the array or the array itself. A local attacker could potentially trigger this failure path to exhaust kernel memory. The issue has been resolved by adding a proper cleanup routine that iterates through the array to free allocated memory before returning an error.

Affected products

  • Linux Linux Kernel 2.6.22 to 6.8.2

Timeline

  • 2024-05-17: advisory: NVD publication date
  • 2024-02-05: patched: Initial fix committed to Linux kernel stable tree

References

Related threats