Executive brief
A vulnerability was identified in the Linux kernel's Intel Wi-Fi driver (iwlwifi) that could cause a system crash. The issue occurs when the system attempts to remove a wireless network link and incorrectly handles internal memory pointers. This could lead to a denial-of-service scenario where the operating system stops functioning correctly.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel's iwlwifi driver within the 'iwl_mld_remove_link' function in 'drivers/net/wireless/intel/iwlwifi/mld/link.c'. The root cause is that the 'link->fw_id' is accessed at the start of the function before the 'link' pointer is validated against NULL. An attacker or a specific system state triggering link removal could cause a kernel panic. The fix involves reordering the function logic to ensure the pointer is validated before use and delaying the memory deallocation (kfree_rcu) until the end of the operation. Patches have been released for various stable branches including 6.18.34 and 7.0.11.
Affected products
- Linux Linux Kernel 6.18.34, 7.0.11, 7.1
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory