CVE-2024-35912: wifi: iwlwifi: mvm: rfi: fix potential response leaks

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: rfi: fix potential response leaks

If the rx payload length check fails, or if kmemdup() fails,
we still need to free the command response. Fix that.

Classification

CVE ID: CVE-2024-35912

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.83% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/28db0ae86cb91a4ab0e855cff779daead936b7d5
https://git.kernel.org/stable/c/99a75d75007421d8e08ba139e24f77395cd08f62
https://git.kernel.org/stable/c/c0a40f2f8eba07416f695ffe2011bf3f8b0b6dc8
https://git.kernel.org/stable/c/f7f0e784894dfcb265f0f9fa499103b0ca7eabde
https://git.kernel.org/stable/c/06a093807eb7b5c5b29b6cff49f8174a4e702341

Timeline