Executive brief
A vulnerability in the Linux kernel's Realtek WiFi driver (rtw88) could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system fails to properly synchronize the loading of wireless firmware, leading to a memory error known as a 'use-after-free'. This could impact system stability and the security of data handled by the wireless network interface.
Technical details
A use-after-free (UAF) vulnerability exists in the rtw88 driver within the Linux kernel. The root cause is located in 'rtw_wait_firmware_completion()', which failed to wait for both regular and Wake-on-WLAN (WoWLAN) firmware loading attempts to finish. If 'rtw_usb_intf_init()' fails during the USB probing process, 'rtw_usb_disconnect()' may trigger 'ieee80211_free_hw()' while a firmware loading callback is still active. An attacker with local access could exploit this race condition to achieve arbitrary code execution or cause a kernel panic. The vulnerability has been addressed by ensuring the driver waits for all firmware completion signals before proceeding with cleanup.
Affected products
- Linux Linux Kernel 5.6 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2
Timeline
- 2024-07-26: disclosed: Initial patch submitted by Dmitry Antipov
- 2024-10-21: advisory: CVE-2024-47718 published
References
- https://git.kernel.org/stable/c/0e735a4c6137262bcefe45bb52fde7b1f5fc6c4d
- https://git.kernel.org/stable/c/1b8178a2ae272256ea0dc4f940320a81003535e2
- https://git.kernel.org/stable/c/7887ad11995a4142671cc49146db536f923c8568
- https://git.kernel.org/stable/c/9432185540bafd42b7bfac6e6ef2f0a0fb4be447
- https://git.kernel.org/stable/c/a0c1e2da652cf70825739bc12d49ea15805690bf
- https://git.kernel.org/stable/c/ceaab3fb64d6a5426a3db8f87f3e5757964f2532
- https://git.kernel.org/stable/c/e9a78d9417e167410d6fb83c4e908b077ad8ba6d