cbcvebase.
CVE-2024-49930
published 2024-10-21

CVE-2024-49930: In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix array out-of-bound access in SoC stats Currently, the…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix array out-of-bound access in SoC stats Currently, the ath11k_soc_dp_stats::hal_reo_error array is defined with a maximum size of DP_REO_DST_RING_MAX. However, the ath11k_dp_process_rx() function access ath11k_soc_dp_stats::hal_reo_error using the REO destination SRNG ring ID, which is incorrect. SRNG ring ID differ from normal ring ID, and this usage leads to out-of-bounds array access. To fix this issue, modify ath11k_dp_process_rx() to use the normal ring ID directly instead of the SRNG ring ID to avoid out-of-bounds array access. Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 0f26f26944035ec67546a944f182cbad6577a9c00f26f26944035ec67546a944f182cbad6577a9c0
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 4dd732893bd38cec51f887244314e2b47f0d658f4dd732893bd38cec51f887244314e2b47f0d658f
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 73e235728e515faccc104b0153b47d0f263b334473e235728e515faccc104b0153b47d0f263b3344
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 7a552bc2f3efe2aaf77a85cb34cdf4a63d81a1a77a552bc2f3efe2aaf77a85cb34cdf4a63d81a1a7
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 6045ef5b4b00fee3629689f791992900a1c940096045ef5b4b00fee3629689f791992900a1c94009
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 01b77f5ee11c89754fb836af8f76799d3b72ae2f01b77f5ee11c89754fb836af8f76799d3b72ae2f
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 69f253e46af98af17e3efa3e5dfa72fcb7d1983d69f253e46af98af17e3efa3e5dfa72fcb7d1983d
linuxlinux_kernel< 5.10.2275.10.227
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.36.11.3
linuxlinux_kernel>= 6.2 < 6.6.556.6.55
linuxlinux_kernel>= 6.7 < 6.10.146.10.14
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.57.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.