Executive brief
A vulnerability exists in the Linux kernel's Intel Wi-Fi driver (iwlwifi) that could allow a local user to compromise the system. The issue stems from how the driver handles recovery commands for Wi-Fi hardware, failing to properly validate response sizes and manage memory. This could lead to system instability, data exposure, or unauthorized access to sensitive information.
Technical details
A vulnerability in the Linux kernel's iwlwifi MVM driver is caused by improper response handling in the iwl_mvm_send_recovery_cmd() function. Specifically, the driver fails to validate the size of response packets received from the firmware and does not free the associated response buffer (SKB). An attacker with local access could potentially exploit these memory management issues to trigger a kernel heap overflow or cause a memory leak leading to a denial of service. The fix involves migrating to the iwl_mvm_send_cmd_status() function, which correctly implements size validation and buffer deallocation.
Affected products
- Linux Linux Kernel 5.1 to 5.4.285, 5.5 to 5.10.229, 5.11 to 5.15.171, 5.16 to 6.1.116, 6.2 to 6.6.60, 6.7 to 6.11.7
Timeline
- 2024-11-19: disclosed
- 2024-11-19: advisory
- 2024-10-25: patched
References
- https://git.kernel.org/stable/c/07a6e3b78a65f4b2796a8d0d4adb1a15a81edead
- https://git.kernel.org/stable/c/3eb986c64c6bfb721950f9666a3b723cf65d043f
- https://git.kernel.org/stable/c/3f45d590ccbae6dfd6faef54efe74c30bd85d3da
- https://git.kernel.org/stable/c/45a628911d3c68e024eed337054a0452b064f450
- https://git.kernel.org/stable/c/64d63557ded6ff3ce72b18ab87a6c4b1b652161c
- https://git.kernel.org/stable/c/9480c3045f302f43f9910d2d556d6cf5a62c1822
- https://git.kernel.org/stable/c/9c98ee7ea463a838235e7a0e35851b38476364f2