-

CVE-2026-80948

wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()

In iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses
the out_free_eeprom_blob label. Consequently, error paths triggered after
successfully parsing the EEPROM free priv->nvm_data but leak
priv->eeprom_blob.

Fix this memory leak by reordering the error handling labels so
that out_free_eeprom falls through to out_free_eeprom_blob.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc6.

An x86_64 allyesconfig build showed no new warnings. As we do not have
supported Intel DVM wireless hardware and firmware to test with, no
runtime testing was able to be performed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 26a7ca9a71a3f7e1826de96b1a1e907123e11b07
Version < 84ba017a1e1ea7896ed1e3258c947bdbfc5299c5
Status affected
Version 26a7ca9a71a3f7e1826de96b1a1e907123e11b07
Version < ad2a9fdca4a7100472be82ee6048c616fc589720
Status affected
Version 26a7ca9a71a3f7e1826de96b1a1e907123e11b07
Version < 67105abd6195a685a84dcb8a5daf54a1f4bfdb60
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.6
Status affected
Version 0
Version < 3.6
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.113
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/84ba017a1e1ea7896ed1e3258c947bdbfc5299c5
https://git.kernel.org/stable/c/ad2a9fdca4a7100472be82ee6048c616fc589720
https://git.kernel.org/stable/c/67105abd6195a685a84dcb8a5daf54a1f4bfdb60