cbcvebase.
CVE-2024-41072
published 2024-07-29

CVE-2024-41072: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: wext: add extra SIOCSIWSCAN data check In 'cfg80211_wext_siwscan()', add…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: wext: add extra SIOCSIWSCAN data check In 'cfg80211_wext_siwscan()', add extra check whether number of channels passed via 'ioctl(sock, SIOCSIWSCAN, ...)' doesn't exceed IW_MAX_FREQUENCIES and reject invalid request with -EINVAL otherwise.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < b02ba9a0b55b762bd04743a22f3d9f9645005e79b02ba9a0b55b762bd04743a22f3d9f9645005e79
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < de5fcf757e33596eed32de170ce5a93fa44dd2acde5fcf757e33596eed32de170ce5a93fa44dd2ac
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < 6295bad58f988eaafcf0e6f8b198a580398acb3b6295bad58f988eaafcf0e6f8b198a580398acb3b
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < a43cc0558530b6c065976b6b9246f512f8d3593ba43cc0558530b6c065976b6b9246f512f8d3593b
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < 001120ff0c9e3557dee9b5ee0d358e0fc189996f001120ff0c9e3557dee9b5ee0d358e0fc189996f
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < fe9644efd86704afe50e56b64b609de340ab7c95fe9644efd86704afe50e56b64b609de340ab7c95
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < 35cee10ccaee5bd451a480521bbc25dc9f07fa5b35cee10ccaee5bd451a480521bbc25dc9f07fa5b
linuxlinux>= b2e3abdc708f8c0eff194af25362fdb239abe241 < 6ef09cdc5ba0f93826c09d810c141a8d103a80fc6ef09cdc5ba0f93826c09d810c141a8d103a80fc
linuxlinux_kernel< 4.19.3194.19.319
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.11-16.9.11-1
linuxlinux_kernel>= 0 < 6.9.11-16.9.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 4.20 < 5.4.2815.4.281
linuxlinux_kernel>= 5.11 < 5.15.1645.15.164
linuxlinux_kernel>= 5.16 < 6.1.1016.1.101
linuxlinux_kernel>= 5.5 < 5.10.2235.10.223
linuxlinux_kernel>= 6.2 < 6.6.426.6.42

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.