In the Linux kernel, the following vulnerability has been resolved:wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()1. The size of the response packet is not validated.2. The response buffer is not freed.Resolve these issues by switching to iwl_mvm_send_cmd_status(),which handles both size validation and frees the buffer.
No PoCs from references.
- https://github.com/w4zu/Debian_security