Impact
The rtlwifi PCI driver in the Linux kernel contained a flaw where the error handling path used an incorrect goto label, causing cleanup functions to be skipped. As a result, resources such as rfkill devices, hardware registrations, and debug entries were not freed when a probe failed, leading to memory leaks that could accumulate and potentially destabilize or crash the kernel. The weakness is improper cleanup during driver initialization, mapped to CWE-401.
Affected Systems
All Linux kernel implementations that include the rtlwifi driver prior to the fix are potentially affected. This encompasses kernel packages used by open‑source distributions and vendors that ship kernels with the buggy rtlwifi module. Any kernel lacking the patch commit remains vulnerable, regardless of distribution or version number, due to the lack of explicit version restrictions.
Risk and Exploitability
The CVSS base score of 7.0 rates this as medium severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation would generally require local or privileged access to trigger a probe failure or to influence module loading, making remote exploitation unlikely. The practical risk remains moderate and is contingent on an attacker’s ability to load or manipulate the vulnerable driver.
OpenCVE Enrichment
Debian DLA
Debian DSA