cbcvebase.
CVE-2024-53059
published 2024-11-19

CVE-2024-53059: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd() 1. The size of the…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd() 1. The size of the response packet is not validated. 2. The response buffer is not freed. Resolve these issues by switching to iwl_mvm_send_cmd_status(), which handles both size validation and frees the buffer.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 9c98ee7ea463a838235e7a0e35851b38476364f29c98ee7ea463a838235e7a0e35851b38476364f2
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 45a628911d3c68e024eed337054a0452b064f45045a628911d3c68e024eed337054a0452b064f450
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 3f45d590ccbae6dfd6faef54efe74c30bd85d3da3f45d590ccbae6dfd6faef54efe74c30bd85d3da
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 64d63557ded6ff3ce72b18ab87a6c4b1b652161c64d63557ded6ff3ce72b18ab87a6c4b1b652161c
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 3eb986c64c6bfb721950f9666a3b723cf65d043f3eb986c64c6bfb721950f9666a3b723cf65d043f
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 9480c3045f302f43f9910d2d556d6cf5a62c18229480c3045f302f43f9910d2d556d6cf5a62c1822
linuxlinux>= f130bb75d8817c560b48c4d1a0e5279968a0859d < 07a6e3b78a65f4b2796a8d0d4adb1a15a81edead07a6e3b78a65f4b2796a8d0d4adb1a15a81edead
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.1 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1715.15.171
linuxlinux_kernel>= 5.16 < 6.1.1166.1.116
linuxlinux_kernel>= 5.5 < 5.10.2295.10.229
linuxlinux_kernel>= 6.2 < 6.6.606.6.60
linuxlinux_kernel>= 6.7 < 6.11.76.11.7

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.