CVE-2024-27434 — Linux vulnerability
17 documents8 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateJul 4
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: don't set the MFP flag for the GTK
The firmware doesn't need the MFP flag for the GTK, it can even make the
firmware crash. in case the AP is configured with: group cipher TKIP and
MFPC. We would send the GTK with cipher = TKIP and MFP which is of course
not possible.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages9 packages
▶CVEListV5linux/linux5c75a208c2449c6ea24f07610cc052f6a352246c — b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8+4
Patches
🔴Vulnerability Details
7📋Vendor Advisories
8💬Community
1Bugzilla
▶