{
  "entrypoint_kind": "local_kernel_runtime",
  "entrypoint_detail": "iwlwifi module init hook calls the real iwl_pcie_rx_free() twice (nic-init unwind after iwl_pcie_tx_init failure, then teardown/retry) on a live transport object",
  "service_started": false,
  "healthcheck_passed": false,
  "target_path_reached": true,
  "runtime_stack": [
    "qemu-kvm",
    "linux v6.18.52 + KASAN/SLUB_DEBUG/DEBUG_OBJECTS",
    "iwlwifi.ko (vulnerable and stable-fixed builds)"
  ],
  "target_identity": {
    "repository_url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
    "commit_sha": "8f3741e6feb045da5b406df0a80b42a1adfb289b",
    "target_digest": "383a49d38777fa10b3cb93d2cc6c3ad43991c83dd0ae2893ac51496e72f5c064",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "logs/vm_vuln_attempt1.log",
    "logs/vm_vuln_attempt2.log",
    "logs/vm_fixed_attempt1.log",
    "logs/vm_fixed_attempt2.log"
  ],
  "artifact_sha256": {
    "logs/vm_vuln_attempt1.log": "1e15edac81118a712732bf58ef4c7f6a9015c7c2ba941d96700ce30ca4fff50b",
    "logs/vm_vuln_attempt2.log": "24b2a12ca9ae7a25557c26389a288a928a7bd1c22767731beea08f5fa2950a7c",
    "logs/vm_fixed_attempt1.log": "64efd5af25bc6f471a2c178e85d37a5200763f93893bdfef41c3881c1bab416b",
    "logs/vm_fixed_attempt2.log": "3b5d560b9e278c649c4d4e827f0e791d9c1a870be17b3904865410c308365c8c"
  },
  "notes": "vulnerable kernel: 2/2 attempts produced KASAN use-after-free in iwl_pcie_free_rbs_pool plus stale-rxq dereference oops (BAD_PAGE, dma_free_attrs GPF) via iwl_pcie_rx_free; fixed kernel: 2/2 clean completions (pointers NULLed, sentinel early-return)"
}