Executive brief
A vulnerability in the Linux kernel's Intel Wi-Fi driver (iwlwifi) could allow a local user to cause a system crash or potentially execute unauthorized actions. The issue stems from improper error handling during the initialization of the Wi-Fi hardware, which can lead to memory corruption. This affects systems using specific Intel wireless adapters and could impact system stability and data integrity.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's iwlwifi driver within the 'iwl_op_mode_dvm_start()' function in 'drivers/net/wireless/intel/iwlwifi/dvm/main.c'. The root cause is a failure to preserve and return the correct error code when 'iwl_setup_deferred_work()' fails; the function incorrectly returns NULL (ERR_PTR(0)) instead of a proper error pointer. This improper return value can lead to a use-after-free condition involving debugfs components during cleanup or subsequent operations. An attacker with local access could exploit this to cause a denial of service (system crash) or potentially achieve privilege escalation. Patches have been released for various stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.12.y.
Affected products
- Linux Linux Kernel 5.4.297 to 5.5, 5.10.241 to 5.11, 5.15.190 to 5.16, 6.1.148 to 6.2, 6.6.102 to 6.7, 6.12.42 to 6.13
Timeline
- 2025-08-22: disclosed
- 2025-08-22: advisory
- 2025-08-15: patched: Patched in stable branches