cbcvebase.
CVE-2024-36922
published 2024-05-30

CVE-2024-36922: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: read txq->read_ptr under lock If we read txq->read_ptr without lock, we can…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.35%
27.5th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: read txq->read_ptr under lock If we read txq->read_ptr without lock, we can read the same value twice, then obtain the lock, and reclaim from there to two different places, but crucially reclaim the same entry twice, resulting in the WARN_ONCE() a little later. Fix that by reading txq->read_ptr under lock.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.11-1 (forky)linux 6.8.11-1 (forky)
linuxlinux
linuxlinux>= 7b3e42ea2eadd41cc9d6363a9813b8ba8ab6f0e6 < f30e8af109818c9db08cbcc46eb9713fe4b530baf30e8af109818c9db08cbcc46eb9713fe4b530ba
linuxlinux>= 7b3e42ea2eadd41cc9d6363a9813b8ba8ab6f0e6 < aab7b39fcac5f6165f6434bcbb56bb7865d4ad2baab7b39fcac5f6165f6434bcbb56bb7865d4ad2b
linuxlinux>= 7b3e42ea2eadd41cc9d6363a9813b8ba8ab6f0e6 < b83db8e756dec68a950ed2f056248b1704b3deaab83db8e756dec68a950ed2f056248b1704b3deaa
linuxlinux>= 7b3e42ea2eadd41cc9d6363a9813b8ba8ab6f0e6 < 43d07103df670484cdd26f9588eabef80f69db8943d07103df670484cdd26f9588eabef80f69db89
linuxlinux>= 7b3e42ea2eadd41cc9d6363a9813b8ba8ab6f0e6 < c2ace6300600c634553657785dfe5ea0ed688ac2c2ace6300600c634553657785dfe5ea0ed688ac2
linuxlinux_kernel< 6.6.316.6.31
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.7 < 6.8.106.8.10
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure-5.15
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.