CVE-2024-35811Use After Free in Kernel

CWE-416Use After Free31 documents6 sources
Severity
5.5MEDIUMNVD
OSV7.8OSV7.0OSV6.5OSV4.3
EPSS
0.0%
top 99.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateJul 4

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach This is the candidate patch of CVE-2023-47233 : https://nvd.nist.gov/vuln/detail/CVE-2023-47233 In brcm80211 driver,it starts with the following invoking chain to start init a timeout worker: ->brcmf_usb_probe ->brcmf_usb_probe_cb ->brcmf_attach ->brcmf_bus_started ->brcmf_cfg80211_attach ->wl_init_priv ->brcmf_init_escan ->INIT_WORK(&cfg->escan_timeout_work, br

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel3.74.19.312+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-186.206+2
debiandebian/linux< linux 6.1.85-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

15
OSV
linux-oracle vulnerabilities2024-07-04
OSV
linux-azure, linux-azure-fde vulnerabilities2024-06-14
OSV
linux-azure, linux-gke vulnerabilities2024-06-14
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, l2024-06-12
OSV
linux-oem-6.8 vulnerabilities2024-06-11

📋Vendor Advisories

15
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-07-04
Ubuntu
Linux kernel vulnerabilities2024-06-14
Ubuntu
Linux kernel (Azure) vulnerabilities2024-06-14
Ubuntu
Linux kernel vulnerabilities2024-06-12
Ubuntu
Linux kernel (OEM) vulnerabilities2024-06-11