cbcvebase.
CVE-2024-27056
published 2024-05-01

CVE-2024-27056: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: ensure offloading TID queue exists The resume code path assumes that…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: ensure offloading TID queue exists The resume code path assumes that the TX queue for the offloading TID has been configured. At resume time it then tries to sync the write pointer as it may have been updated by the firmware. In the unusual event that no packets have been send on TID 0, the queue will not have been allocated and this causes a crash. Fix this by ensuring the queue exist at suspend time.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= ba7136f3f9e849e5776429317bf45ac3d4cfa3f7 < 4903303f25f48b5a1e34e6324c7fae9ccd6b959a4903303f25f48b5a1e34e6324c7fae9ccd6b959a
linuxlinux>= ba7136f3f9e849e5776429317bf45ac3d4cfa3f7 < 35afffaddbe8d310dc61659da0b1a337b0d0addc35afffaddbe8d310dc61659da0b1a337b0d0addc
linuxlinux>= ba7136f3f9e849e5776429317bf45ac3d4cfa3f7 < ed35a509390ef4011ea2226da5dd6f62b73873b5ed35a509390ef4011ea2226da5dd6f62b73873b5
linuxlinux>= ba7136f3f9e849e5776429317bf45ac3d4cfa3f7 < 78f65fbf421a61894c14a1b91fe2fb4437b3fe5f78f65fbf421a61894c14a1b91fe2fb4437b3fe5f
linuxlinux_kernel< 6.1.1326.1.132
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 6.2 < 6.6.856.6.85
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.