GHSA-fgmq-vv8f-hphcHighCVSS 7.0

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: pcie: null RX...

Published
September 24, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: pcie: null RX pointers after free

When iwl_pcie_tx_init() fails after RX init, nic init unwinds via iwl_pcie_rx_free().

The freed RX members stayed non-NULL on the live transport object, so later teardown or retry could touch stale RX state. Set rx_pool, global_table, rxq, and alloc_page to NULL after free to make repeated cleanup and retry paths safe.

🔗 References (5)