Executive brief
A vulnerability in the Linux kernel's Intel Wi-Fi driver (iwlwifi) could allow a local attacker to cause a system crash. The issue occurs when the Wi-Fi hardware's firmware sends a specific notification that claims to contain more data than is actually present, leading the system to read memory outside of the intended area. This primarily impacts system stability and availability.
Technical details
An out-of-bounds read vulnerability exists in the `iwl_mvm_mfu_assert_dump_notif` function within `drivers/net/wireless/intel/iwlwifi/mvm/fw.c`. The root cause is a lack of validation on the `data_size` field provided by firmware notifications; if the firmware reports a size larger than the actual allocated buffer, the driver performs an out-of-bounds read while attempting to print or process the buffer. This was identified by KFENCE. The fix involves removing the unsafe buffer printing logic. While the attack vector is listed as local, it specifically requires the ability to influence or receive malformed firmware notifications, typically resulting in a kernel panic or memory corruption. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.12 to 4.19.317, 4.20 to 5.4.279, 5.5 to 5.10.221, 5.11 to 5.15.162, 5.16 to 6.1.95, 6.2 to 6.6.35, 6.7 to 6.9.6, 6.10-rc1, 6.10-rc2
Timeline
- 2024-05-13: patched: Initial patch submitted by Intel
- 2024-07-12: disclosed: CVE published
References
- https://git.kernel.org/stable/c/15b37c6fab9d5e40ac399fa1c725118588ed649c
- https://git.kernel.org/stable/c/46c59a25337049a2a230ce7f7c3b9f21d0aaaad7
- https://git.kernel.org/stable/c/4bb95f4535489ed830cf9b34b0a891e384d1aee4
- https://git.kernel.org/stable/c/6532f18e66b384b8d4b7e5c9caca042faaa9e8de
- https://git.kernel.org/stable/c/65686118845d427df27ee83a6ddd4885596b0805
- https://git.kernel.org/stable/c/a05018739a5e6b9dc112c95bd4c59904062c8940
- https://git.kernel.org/stable/c/a8bc8276af9aeacabb773f0c267cfcdb847c6f2d