cbcvebase.
CVE-2024-40942
published 2024-07-12

CVE-2024-40942: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects The hwmp code use objects of type…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects The hwmp code use objects of type mesh_preq_queue, added to a list in ieee80211_if_mesh, to keep track of mpath we need to resolve. If the mpath gets deleted, ex mesh interface is removed, the entries in that list will never get cleaned. Fix this by flushing all corresponding items of the preq_queue in mesh_path_flush_pending(). This should take care of KASAN reports like this: unreferenced object 0xffff00000668d800 (size 128): comm "kworker/u8:4", pid 67, jiffies 4295419552 (age 1836.444s) hex dump (first 32 bytes): 00 1f 05 09 00 00 ff ff 00 d5 68 06 00 00 ff ff ..........h..... 8e 97 ea eb 3e b8 01 00 00 00 00 00 00 00 00 00 ....>........... backtrace: [] __kmem_cache_alloc_node+0x1e0/0x35c [] kmalloc_trace+0x34/0x80 [] mesh_queue_preq+0x44/0x2a8 [] mesh_nexthop_resolve+0x198/0x19c [] ieee80211_xmit+0x1d0/0x1f4 [] __ieee80211_subif_start_xmit+0x30c/0x764 [] ieee80211_subif_start_xmit+0x9c/0x7a4 [] dev_hard_start_xmit+0x174/0x440 [] __dev_queue_xmit+0xe24/0x111c [] batadv_send_skb_packet+0x180/0x1e4 [] batadv_v_elp_periodic_work+0x2f4/0x508 [] process_one_work+0x4b8/0xa1c [] worker_thread+0x9c/0x634 [] kthread+0x1bc/0x1c4 [] ret_from_fork+0x10/0x20 unreferenced object 0xffff000009051f00 (size 128): comm "kworker/u8:4", pid 67, jiffies 4295419553 (age 1836.440s) hex dump (first 32 bytes): 90 d6 92 0d 00 00 ff ff 00 d8 68 06 00 00 ff ff ..........h..... 36 27 92 e4 02 e0 01 00 00 58 79 06 00 00 ff ff 6'.......Xy..... backtrace: [] __kmem_cache_alloc_node+0x1e0/0x35c [] kmalloc_trace+0x34/0x80 [] mesh_queue_preq+0x44/0x2a8 [] mesh_nexthop_resolve+0x198/0x19c [] ieee80211_xmit+0x1d0/0x1f4 [] __ieee80211_subif_start_xmit+0x30c/0x764 [] ieee80211_subif_start_xmit+0x9c/0x7a4 [] dev_hard_start_xmit+0x174/0x440 [] __dev_queue_xmit+0xe24/0x111c [] batadv_send_skb_packet+0x180/0x1e4 [] batadv_v_elp_periodic_work+0x2f4/0x508 [] process_one_work+0x4

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < 377dbb220edc8421b7960691876c5b3bef62f89b377dbb220edc8421b7960691876c5b3bef62f89b
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < ec79670eae430b3ffb7e0a6417ad7657728b8f95ec79670eae430b3ffb7e0a6417ad7657728b8f95
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < 7518e20a189f8659b8b83969db4d33a4068fcfc37518e20a189f8659b8b83969db4d33a4068fcfc3
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < c4c865f971fd4a255208f57ef04d814c2ae9e0dcc4c865f971fd4a255208f57ef04d814c2ae9e0dc
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < 617dadbfb2d3e152c5753e28356d189c9d6f33c0617dadbfb2d3e152c5753e28356d189c9d6f33c0
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < 63d5f89bb5664d60edbf8cf0df911aaae8ed96a463d5f89bb5664d60edbf8cf0df911aaae8ed96a4
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < d81e244af521de63ad2883e17571b789c39b6549d81e244af521de63ad2883e17571b789c39b6549
linuxlinux>= 050ac52cbe1f3de2fb0d06f02c7919ae1f691c9e < b7d7f11a291830fdf69d3301075dd0fb347ced84b7d7f11a291830fdf69d3301075dd0fb347ced84
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 2.6.26 < 4.19.3174.19.317
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.356.6.35

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.