Executive brief
The Intel WiFi driver (iwlwifi) in the Linux kernel is used to manage wireless network connectivity on systems with Intel network adapters. A flaw in the firmware debug logging allocation function could cause a division by zero error, potentially leading to a kernel crash or denial of service on affected systems.
Technical details
The vulnerability is a division by zero flaw in the iwl_dbg_tlv_alloc_fragments() function within the iwlwifi driver. The root cause is missing validation checks that allow the num_frags variable to be zero before it is used in a DIV_ROUND_UP() macro call, which performs integer division. The function processes firmware debug telemetry configuration and is reachable when the kernel loads or configures the iwlwifi driver; no user interaction or network access is required. An attacker with the ability to influence firmware configuration data or a system administrator with the ability to load malicious firmware could trigger this condition to cause a kernel panic. The patch adds validation to return an error (-EIO) if req_size or num_frags is zero, preventing the division by zero.
Affected products
- Linux Linux kernel Multiple versions containing drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c
Timeline
- 2026-09-17: disclosed
- 2026-09-14: patched