CVE-2024-35789 — Use After Free in Linux
Severity
7.8HIGHNVD
OSV7.0OSV5.5
EPSS
0.1%
top 79.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes
When moving a station out of a VLAN and deleting the VLAN afterwards, the
fast_rx entry still holds a pointer to the VLAN's netdev, which can cause
use-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx
after the VLAN change.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages5 packages
▶CVEListV5linux/linuxa7f1721684628b8ae6015bca9a176046ee6f30cc — ea9a0cfc07a7d3601cc680718d9cff0d6927a921+11
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
20📋Vendor Advisories
20💬Community
1Bugzilla▶
CVE-2024-35789 kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes↗2024-05-17