Impact
A memory leak occurs in the iwlwifi driver of the Linux kernel when the iwl_op_mode_dvm_start function jumps to out_free_eeprom and bypasses out_free_eeprom_blob. The priv->eeprom_blob remains allocated after a failed EEPROM parse, causing gradual depletion of kernel memory. This leak can reduce available memory for both user and kernel allocations and may lead to a denial‑of‑service. The weakness is CWE‑772 and the CVSS score is 4.7.
Affected Systems
All Linux kernel builds containing the iwlwifi driver for Intel DVM wireless hardware are affected. The issue exists in releases up to and including version 7.1‑rc6 and was fixed in a subsequent commit. Distributions shipping kernels with the older iwlwifi code are potentially vulnerable until the patch is applied.
Risk and Exploitability
Exploitation requires triggering error conditions during the EEPROM parsing routine, which is normally invoked during driver initialization. The exploit would need repeated failures to drain sufficient memory, making a single‑shot attack unlikely. The EPSS score is < 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The moderate CVSS score and low prevalence suggest the risk is primarily one of availability rather than remote code execution.
OpenCVE Enrichment