cbcvebase.
CVE-2024-46755
published 2024-09-18

CVE-2024-46755: In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id() mwifiex_get_priv_by_id() returns the priv pointer corresponding to the bss_num and bss_type, but without checking if the priv is actually currently in use. Unused priv pointers do not have a wiphy attached to them which can lead to NULL pointer dereferences further down the callstack. Fix this by returning only used priv pointers which have priv->bss_mode set to something else than NL80211_IFTYPE_UNSPECIFIED. Said NULL pointer dereference happened when an Accesspoint was started with wpa_supplicant -i mlan0 with this config: network={ ssid="somessid" mode=2 frequency=2412 key_mgmt=WPA-PSK WPA-PSK-SHA256 proto=RSN group=CCMP pairwise=CCMP psk="12345678" } When waiting for the AP to be established, interrupting wpa_supplicant with and starting it again this happens: | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000140 | Mem abort info: | ESR = 0x0000000096000004 | EC = 0x25: DABT (current EL), IL = 32 bits | SET = 0, FnV = 0 | EA = 0, S1PTW = 0 | FSC = 0x04: level 0 translation fault | Data abort info: | ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 | CM = 0, WnR = 0, TnD = 0, TagAccess = 0 | GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 | user pgtable: 4k pages, 48-bit VAs, pgdp=0000000046d96000 | [0000000000000140] pgd=0000000000000000, p4d=0000000000000000 | Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP | Modules linked in: caam_jr caamhash_desc spidev caamalg_desc crypto_engine authenc libdes mwifiex_sdio +mwifiex crct10dif_ce cdc_acm onboard_usb_hub fsl_imx8_ddr_perf imx8m_ddrc rtc_ds1307 lm75 rtc_snvs +imx_sdma caam imx8mm_thermal spi_imx error imx_cpufreq_dt fuse ip_tables x_tables ipv6 | CPU: 0 PID: 8 Comm: kworker/0:1 Not tainted 6.9.0-00007-g937242013fce-dirty #18 | Hardware name: somemachine (DT) | Workqueue: events sdio_irq_work | pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DI

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < a12cf97cbefa139ef8d95081f2ea047cbbd74b7aa12cf97cbefa139ef8d95081f2ea047cbbd74b7a
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < d834433ff313838a259bb6607055ece87b895b66d834433ff313838a259bb6607055ece87b895b66
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < 9813770f25855b866b8ead8155b8806b2db70f6d9813770f25855b866b8ead8155b8806b2db70f6d
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < cb67b2e51b75f1a17bee7599c8161b96e1808a70cb67b2e51b75f1a17bee7599c8161b96e1808a70
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < 1a05d8d02cfa3540ea5dbd6b39446bd3f515521f1a05d8d02cfa3540ea5dbd6b39446bd3f515521f
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < c2618dcb26c7211342b54520b5b148c0d3471c8ac2618dcb26c7211342b54520b5b148c0d3471c8a
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < c16916dd6c16fa7e13ca3923eb6b9f50d848ad03c16916dd6c16fa7e13ca3923eb6b9f50d848ad03
linuxlinux>= 93a1df48d224296fb527d32fbec4d5162828feb4 < c145eea2f75ff7949392aebecf7ef0a81c1f6c14c145eea2f75ff7949392aebecf7ef0a81c1f6c14
linuxlinux_kernel< 4.19.3224.19.322
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.20 < 5.4.2845.4.284
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110
linuxlinux_kernel>= 5.5 < 5.10.2265.10.226
linuxlinux_kernel>= 6.2 < 6.6.516.6.51
linuxlinux_kernel>= 6.7 < 6.10.106.10.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.