Junglewise Threat Intelligence

CVE-2024-47718: Linux Kernel rtw88 use-after-free in firmware loading

CVE-2024-47718 · Severity: high · CVSS 7.8 · Published 2024-10-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Realtek WiFi driver (rtw88) could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system fails to properly synchronize the loading of wireless firmware, leading to a memory error known as a 'use-after-free'. This could impact system stability and the security of data handled by the wireless network interface.

Technical details

A use-after-free (UAF) vulnerability exists in the rtw88 driver within the Linux kernel. The root cause is located in 'rtw_wait_firmware_completion()', which failed to wait for both regular and Wake-on-WLAN (WoWLAN) firmware loading attempts to finish. If 'rtw_usb_intf_init()' fails during the USB probing process, 'rtw_usb_disconnect()' may trigger 'ieee80211_free_hw()' while a firmware loading callback is still active. An attacker with local access could exploit this race condition to achieve arbitrary code execution or cause a kernel panic. The vulnerability has been addressed by ensuring the driver waits for all firmware completion signals before proceeding with cleanup.

Affected products

  • Linux Linux Kernel 5.6 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2

Timeline

  • 2024-07-26: disclosed: Initial patch submitted by Dmitry Antipov
  • 2024-10-21: advisory: CVE-2024-47718 published

References

Related threats