Junglewise Threat Intelligence

CVE-2024-58072: Linux Kernel rtlwifi use-after-free in check_buddy_priv

CVE-2024-58072 · Severity: high · CVSS 7.8 · Published 2025-03-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Realtek Wi-Fi driver (rtlwifi) could allow a local user to cause a system crash or potentially execute unauthorized code. The issue stems from how the driver manages internal data when a hardware initialization step fails, leading to memory corruption. This affects systems using certain Realtek wireless network adapters.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's rtlwifi driver due to improper management of a global list of private data structures. When a device 'probe' (initialization) fails, the driver fails to remove the private data structure from this global list. Consequently, a subsequent probe attempt may access memory that has already been freed. Additionally, the driver lacked proper locking mechanisms for this list, creating a potential race condition. An attacker with local access could exploit this to cause a denial of service (system crash) or potentially achieve privilege escalation. The fix involves removing the unused 'check_buddy_priv' hook and associated global list structures.

Affected products

  • Linux Linux Kernel 3.10 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.76, 6.7 to 6.12.13, 6.13 to 6.13.2

Timeline

  • 2024-12-06: patched: Initial patch submitted to kernel mailing lists
  • 2025-03-06: disclosed: CVE published

References

Related threats