Junglewise Threat Intelligence

CVE-2026-80948: Linux kernel iwlwifi DVM memory leak in mode initialization

CVE-2026-80948 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Intel WiFi driver (iwlwifi) contains a memory leak in the DVM (Distributed Virtual Machine) initialization code. When certain error conditions occur during wireless device startup, allocated memory for EEPROM blob data is not freed, leading to gradual memory consumption and potential denial of service over time.

Technical details

The vulnerability is a classic memory leak in the error-handling path of iwl_op_mode_dvm_start(). When jumping to the out_free_eeprom label during error handling, control flow bypasses the out_free_eeprom_blob label, causing priv->eeprom_blob to be leaked while priv->nvm_data is freed. The issue affects Intel DVM wireless driver initialization and requires a kernel recompile with the fix—a simple reordering of error-handling labels so out_free_eeprom falls through to out_free_eeprom_blob. The bug was detected through automated kernel memory-management analysis and confirmed present in v6.13-rc1 through v7.1-rc6. No runtime testing was performed due to lack of supported hardware.

Affected products

  • Linux Linux kernel v6.13-rc1 through v7.1-rc6 (and earlier affected versions)

Timeline

  • 2026-09-11: disclosed: CVE published
  • 2026-06-24: patched: Patch committed by Dawei Feng

References

Related threats