Executive brief
A vulnerability was identified in the Linux kernel's RSI Wi-Fi driver that could lead to a system crash. The issue occurs during specific shutdown sequences of the wireless driver, where internal processes conflict and attempt to access memory that has already been cleared. This could allow a local user to cause a denial-of-service (system instability or crash).
Technical details
A use-after-free (UAF) vulnerability exists in the RSI Wi-Fi driver within the Linux kernel. The root cause is a race condition in kthread management where both kthread_complete_and_exit() (self-exit) and kthread_stop() (external-stop) are utilized. In rare scenarios where the thread exits itself before the external stop command is processed, the kernel attempts to access the already-freed kthread object. This is resolved by removing the kthread_stop() call in favor of waiting for completion of the self-exit operation. The vulnerability was discovered via syzbot and affects systems using RSI wireless hardware.
Affected products
- Linux Linux Kernel Fixed in versions 16d9f67, 4f4c9b1, 4f9a4ae, 95fcb43, db57a1a
Timeline
- 2026-04-23: patched: Initial patch authored by Jeongjun Park
- 2026-05-28: disclosed: CVE published to NVD dataset
References
- https://git.kernel.org/stable/c/16d9f674c619838bdeae42abc0929c9c5477ea1f
- https://git.kernel.org/stable/c/4f4c9b13c485abd0a2d2c97f9db339d1dd8e147f
- https://git.kernel.org/stable/c/4f9a4ae8d2c198f01611ea376034c326ef43ab56
- https://git.kernel.org/stable/c/95fcb436586dc3c2983537d557ac05bbc6a027f3
- https://git.kernel.org/stable/c/db57a1aa54ff68669781976e4edb045e09e2b65b