cbcvebase.
CVE-2024-27434
published 2024-05-17

CVE-2024-27434: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.7th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP flag for the GTK, it can even make the firmware crash. in case the AP is configured with: group cipher TKIP and MFPC. We would send the GTK with cipher = TKIP and MFP which is of course not possible.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= 5c75a208c2449c6ea24f07610cc052f6a352246c < b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8
linuxlinux>= 5c75a208c2449c6ea24f07610cc052f6a352246c < 40405cbb20eb6541c603e7b3d54ade0a7be9d71540405cbb20eb6541c603e7b3d54ade0a7be9d715
linuxlinux>= 5c75a208c2449c6ea24f07610cc052f6a352246c < 60f6d5fc84a9fd26528a24d8a267fc6a6698b62860f6d5fc84a9fd26528a24d8a267fc6a6698b628
linuxlinux>= 5c75a208c2449c6ea24f07610cc052f6a352246c < e35f316bce9e5733c9826120c1838f4c447b2c4ce35f316bce9e5733c9826120c1838f4c447b2c4c
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.