{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80948","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.804Z","datePublished":"2026-09-11T19:42:19.048Z","dateUpdated":"2026-09-13T06:23:53.340Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:23:53.340Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()\n\nIn iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses\nthe out_free_eeprom_blob label. Consequently, error paths triggered after\nsuccessfully parsing the EEPROM free priv->nvm_data but leak\npriv->eeprom_blob.\n\nFix this memory leak by reordering the error handling labels so\nthat out_free_eeprom falls through to out_free_eeprom_blob.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc6.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\nsupported Intel DVM wireless hardware and firmware to test with, no\nruntime testing was able to be performed."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/dvm/main.c"],"versions":[{"version":"26a7ca9a71a3f7e1826de96b1a1e907123e11b07","lessThan":"84ba017a1e1ea7896ed1e3258c947bdbfc5299c5","status":"affected","versionType":"git"},{"version":"26a7ca9a71a3f7e1826de96b1a1e907123e11b07","lessThan":"ad2a9fdca4a7100472be82ee6048c616fc589720","status":"affected","versionType":"git"},{"version":"26a7ca9a71a3f7e1826de96b1a1e907123e11b07","lessThan":"67105abd6195a685a84dcb8a5daf54a1f4bfdb60","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/iwlwifi/dvm/main.c"],"versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/84ba017a1e1ea7896ed1e3258c947bdbfc5299c5"},{"url":"https://git.kernel.org/stable/c/ad2a9fdca4a7100472be82ee6048c616fc589720"},{"url":"https://git.kernel.org/stable/c/67105abd6195a685a84dcb8a5daf54a1f4bfdb60"}],"title":"wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()","x_generator":{"engine":"bippy-1.2.0"}}}}