# CVE-2026-80948

## Summary

- **CVE ID:** CVE-2026-80948
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()

In iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses
the out_free_eeprom_blob label. Consequently, error paths triggered after
successfully parsing the EEPROM free priv->nvm_data but leak
priv->eeprom_blob.

Fix this memory leak by reordering the error handling labels so
that out_free_eeprom falls through to out_free_eeprom_blob.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc6.

An x86_64 allyesconfig build showed no new warnings. As we do not have
supported Intel DVM wireless hardware and firmware to test with, no
runtime testing was able to be performed.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (0)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (26a7ca9a71a3f7e1826de96b1a1e907123e11b07)
- Linux — Linux (3.6)

## References

- [CNA](https://git.kernel.org/stable/c/84ba017a1e1ea7896ed1e3258c947bdbfc5299c5)
- [CNA](https://git.kernel.org/stable/c/ad2a9fdca4a7100472be82ee6048c616fc589720)
- [CNA](https://git.kernel.org/stable/c/67105abd6195a685a84dcb8a5daf54a1f4bfdb60)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._