Junglewise Threat Intelligence

CVE-2026-64037: Linux Kernel iwlwifi use-after-free in TSO segmentation

CVE-2026-64037 · Severity: info · CVSS 7.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Intel Wi-Fi driver (iwlwifi) for the Linux kernel can cause a system crash or network instability. When certain Wi-Fi features are disabled, the driver incorrectly processes network traffic, leading to a massive flood of tiny data packets. This can overwhelm the system's memory and network processing, potentially resulting in a complete service outage or system failure.

Technical details

A logic error exists in the iwl_mld_tx_tso_segment() function within the iwlwifi driver's MLD sub-driver. When AMSDU is disabled, the driver sets a sentinel value that is not properly handled during TCP Segmentation Offload (TSO) calculations, resulting in a 'num_subframes' value of zero. This zero value propagates to the GSO size, causing the kernel to generate tens of thousands of micro-segments for a single packet. This floods the transmit ring, leading to memory corruption, reference count underflows in the TCP retransmit queue, and subsequent use-after-free or NULL pointer dereference vulnerabilities. The issue is fixed by properly detecting the sentinel value and falling back to standard segmentation.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.33, 7.0.10

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References

Related threats