Executive brief
A vulnerability in the Linux kernel's Realtek Wi-Fi driver (rtlwifi) could allow a local user to cause a system crash or potentially execute unauthorized code. The issue stems from how the driver manages internal data when a hardware initialization step fails, leading to memory corruption. This affects systems using certain Realtek wireless network adapters.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's rtlwifi driver due to improper management of a global list of private data structures. When a device 'probe' (initialization) fails, the driver fails to remove the private data structure from this global list. Consequently, a subsequent probe attempt may access memory that has already been freed. Additionally, the driver lacked proper locking mechanisms for this list, creating a potential race condition. An attacker with local access could exploit this to cause a denial of service (system crash) or potentially achieve privilege escalation. The fix involves removing the unused 'check_buddy_priv' hook and associated global list structures.
Affected products
- Linux Linux Kernel 3.10 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.76, 6.7 to 6.12.13, 6.13 to 6.13.2
Timeline
- 2024-12-06: patched: Initial patch submitted to kernel mailing lists
- 2025-03-06: disclosed: CVE published
References
- https://git.kernel.org/stable/c/006e803af7408c3fc815b0654fc5ab43d34f0154
- https://git.kernel.org/stable/c/1b9cbd8a9ae68b32099fbb03b2d5ffa0c5e0dcc9
- https://git.kernel.org/stable/c/1e39b0486cdb496cdfba3bc89886150e46acf6f4
- https://git.kernel.org/stable/c/2fdac64c3c35858aa8ac5caa70b232e03456e120
- https://git.kernel.org/stable/c/465d01ef6962b82b1f0ad1f3e58b398dbd35c1c1
- https://git.kernel.org/stable/c/543e3e9f2e9e47ded774c74e680f28a0ca362aee
- https://git.kernel.org/stable/c/8e2fcc68fbaab3ad9f5671fee2be0956134b740a