cbcvebase.
CVE-2024-26610
published 2024-03-11

CVE-2024-26610: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.1th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means that if we copy to iwl_fw_ini_trigger_tlv::data + offset while offset is in bytes, we'll write past the buffer.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= cf29c5b66b9f83939367d90679eb68cdfa2f0356 < 05dd9facfb9a1e056752c0901c6e86416037d15a05dd9facfb9a1e056752c0901c6e86416037d15a
linuxlinux>= cf29c5b66b9f83939367d90679eb68cdfa2f0356 < 99a23462fe1a6f709f0fda3ebbe8b6b193ac75bd99a23462fe1a6f709f0fda3ebbe8b6b193ac75bd
linuxlinux>= cf29c5b66b9f83939367d90679eb68cdfa2f0356 < aa2cc9363926991ba74411e3aa0a0ea82c1ffe32aa2cc9363926991ba74411e3aa0a0ea82c1ffe32
linuxlinux>= cf29c5b66b9f83939367d90679eb68cdfa2f0356 < 870171899d75d43e3d14360f3a4850e90a9c289b870171899d75d43e3d14360f3a4850e90a9c289b
linuxlinux>= cf29c5b66b9f83939367d90679eb68cdfa2f0356 < f32a81999d0b8e5ce60afb5f6a3dd7241c17dd67f32a81999d0b8e5ce60afb5f6a3dd7241c17dd67
linuxlinux>= cf29c5b66b9f83939367d90679eb68cdfa2f0356 < cf4a0d840ecc72fcf16198d5e9c505ab7d5a5e4dcf4a0d840ecc72fcf16198d5e9c505ab7d5a5e4d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.766.1.76
linuxlinux_kernel>= 5.5 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.