Executive brief
A vulnerability exists in the Linux kernel's Alienware WMI driver, which manages hardware-specific features for certain Dell and Alienware laptops. Due to a coding error in how the system identifies hardware, the kernel could experience memory issues or crashes. This could allow a local user to disrupt system operations or potentially access sensitive information from the computer's memory.
Technical details
The vulnerability is caused by a missing null terminator (empty member) in the 'awcc_dmi_table' array within the 'alienware-wmi-wmax' driver. In the Linux kernel, DMI matching functions iterate through these arrays until an empty sentinel entry is found; without it, the kernel may perform an out-of-bounds read into adjacent memory. A local attacker with low privileges could exploit this to cause a denial of service (system crash) or potentially leak sensitive kernel memory. The issue was introduced in version 6.15 and has been patched in version 6.15.9 and subsequent releases.
Affected products
- Linux Linux Kernel 6.15 to 6.15.9
Timeline
- 2025-07-07: patched: Initial patch submitted by developer
- 2025-08-22: disclosed: CVE published by kernel.org