cbcvebase.
CVE-2024-27048
published 2024-05-01

CVE-2024-27048: In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: handle pmk_op allocation failure The kzalloc() in brcmf_pmksa_v3_op() will…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.5th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: handle pmk_op allocation failure The kzalloc() in brcmf_pmksa_v3_op() will return null if the physical memory has run out. As a result, if we dereference the null value, the null pointer dereference bug will happen. Return -ENOMEM from brcmf_pmksa_v3_op() if kzalloc() fails for pmk_op.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= a96202acaea47fa8377088e0952bb63bd02a3bab < df62e22c2e27420e8990a4f09e30d7bf56c2036fdf62e22c2e27420e8990a4f09e30d7bf56c2036f
linuxlinux>= a96202acaea47fa8377088e0952bb63bd02a3bab < 9975908315c13bae2f2ed5ba92870fa935180b0e9975908315c13bae2f2ed5ba92870fa935180b0e
linuxlinux>= a96202acaea47fa8377088e0952bb63bd02a3bab < 6138a82f3bccfc67ed7ac059493579fc326c02e56138a82f3bccfc67ed7ac059493579fc326c02e5
linuxlinux>= a96202acaea47fa8377088e0952bb63bd02a3bab < b4152222e04cb8afeeca239c90e3fcaf4c553b42b4152222e04cb8afeeca239c90e3fcaf4c553b42
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.4 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.