CVE-2024-58072
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-58072 affects the rtlwifi driver in the Linux kernel. The vulnerability was introduced by commit 2461c7d60f9f which added a global list of private data structures, and later commit 26634c4b1868 added functionality to manage this list. The issue stems from an unused checkbuddypriv function and associated data structures, where the private data is not properly removed from the list when probe fails (Kernel Git).

Technical details

The vulnerability exists in the rtlwifi driver's handling of private data structures. A race condition can occur on the global list and its corruption during a second probe when the initial probe fails. The issue specifically involves an unused checkbuddypriv hook and associated structures where a lock for the list exists but is never used. When probe fails, the private data remains in the list, potentially leading to access of freed memory during subsequent probes (RedHat).

Impact

The vulnerability could result in accessing freed memory during device initialization when probing the PCI driver. However, the security impact is limited as only privileged users can trigger the vulnerability (RedHat).

Mitigation and workarounds

To mitigate this issue, prevent the rtlwifi module from being loaded. This can be achieved by blacklisting the kernel module to prevent it from loading automatically (RedHat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management