Executive brief
A vulnerability was identified in the Linux kernel's Intel Wi-Fi driver (iwlwifi) that could lead to a system crash or instability. The issue occurs when the system attempts to remove a wireless link, potentially accessing memory that has already been cleared. This could impact the reliability of wireless networking on affected devices.
Technical details
A use-after-free (UAF) vulnerability exists in the iwl_mld_remove_link() function within the drivers/net/wireless/intel/iwlwifi/mld/link.c component of the Linux kernel. The root cause is a race condition where the code calls kfree_rcu() on a 'link' structure and subsequently dereferences that same structure to retrieve 'fw_id'. An attacker within radio range (adjacent) could potentially exploit this timing issue to cause a kernel panic or execute arbitrary code, though the latter is difficult due to the nature of RCU-based freeing. The issue has been resolved by caching the 'fw_id' before the memory is released.
Affected products
- Linux Linux Kernel 6.15 to 6.17.7
Timeline
- 2025-09-23: disclosed: Initial patch authored
- 2025-12-16: advisory: CVE published
- 2025-11-13: patched: Patch committed to stable tree