CVE-2024-43841 — Improper Input Validation in Linux
Severity
3.3LOWNVD
OSV8.8OSV7.1OSV5.5
EPSS
0.0%
top 86.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 17
Latest updateJan 9
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: virt_wifi: avoid reporting connection success with wrong SSID
When user issues a connection with a different SSID than the one
virt_wifi has advertised, the __cfg80211_connect_result() will
trigger the warning: WARN_ON(bss_not_found).
The issue is because the connection code in virt_wifi does not
check the SSID from user space (it only checks the BSSID), and
virt_wifi will call cfg80211_connect_result() with WLAN_STATUS…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4
Affected Packages8 packages
▶CVEListV5linux/linuxc7cdba31ed8b87526db978976392802d3f93110c — 994fc2164a03200c3bf42fb45b3d49d9d6d33a4d+7