In the Linux kernel, the following vulnerability has been resolved:
iwlwifi: fix use-after-free
If no firmware was present at all (or, presumably, all of the firmware files failed to parse), we end up unbinding by calling device_release_driver(), which calls remove(), which then in iwlwifi calls iwl_drv_stop(), freeing the 'drv' struct. However the new code I added will still erroneously access it after it was freed.
Set 'failure=false' in this case to avoid the access, all data was already freed anyway.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Jul 30, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 16, 2024 |
| Ubuntu | — | Upgrade linux-ibmUpgrade linux-oracleUpgrade linux-gkeopUpgrade linux-gcp-5.4Upgrade linux-aws-fipsUpgrade linux-azure-fipsUpgrade linux-gcp-fipsUpgrade linux-hweUpgrade linux-hwe-5.4Upgrade linux-aws-hweUpgrade linuxUpgrade linux-gcp-4.15Upgrade linux-iotUpgrade linux-ibm-5.4Upgrade linux-azureUpgrade linux-aws-5.4Upgrade linux-bluefieldUpgrade linux-azure-5.4Upgrade linux-oracle-5.4Upgrade linux-raspiUpgrade linux-raspi-5.4Upgrade linux-azure-4.15Upgrade linux-gcpUpgrade linux-awsUpgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-fips | Nov 19, 2024 | Jul 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub