cbcvebase.
CVE-2024-43847
published 2024-08-17

CVE-2024-43847: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid memory access while processing fragmented packets The monitor…

PriorityP346high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.79%
52.2th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid memory access while processing fragmented packets The monitor ring and the reo reinject ring share the same ring mask index. When the driver receives an interrupt for the reo reinject ring, the monitor ring is also processed, leading to invalid memory access. Since monitor support is not yet enabled in ath12k, the ring mask for the monitor ring should be removed. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.3-1 (forky)linux 6.10.3-1 (forky)
linuxlinux
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 8126f82dab7bd8b2e04799342b19fff0a1fd85758126f82dab7bd8b2e04799342b19fff0a1fd8575
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 36fc66a7d9ca3e5c6eac25362cac63f83df8bed636fc66a7d9ca3e5c6eac25362cac63f83df8bed6
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 073f9f249eecd64ab9d59c91c4a23cfdcc02afe4073f9f249eecd64ab9d59c91c4a23cfdcc02afe4
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.3 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.