wifi: iwlwifi: read txq->read_ptr under lock
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.3%
exploitation probability
0.3%top 72% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: read txq->read_ptr under lock
If we read txq->read_ptr without lock, we can read the same
value twice, then obtain the lock, and reclaim from there
to two different places, but crucially reclaim the same
entry twice, resulting in the WARN_ONCE() a little later.
Fix that by reading txq->read_ptr under lock.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/43d07103df670484cdd26f9588eabef80f69db89https://git.kernel.org/stable/c/aab7b39fcac5f6165f6434bcbb56bb7865d4ad2bhttps://git.kernel.org/stable/c/b83db8e756dec68a950ed2f056248b1704b3deaahttps://git.kernel.org/stable/c/c2ace6300600c634553657785dfe5ea0ed688ac2https://git.kernel.org/stable/c/f30e8af109818c9db08cbcc46eb9713fe4b530ba