cbcvebase.
CVE-2024-56593
published 2024-12-27

CVE-2024-56593: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() This…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() This patch fixes a NULL pointer dereference bug in brcmfmac that occurs when a high 'sd_sgentry_align' value applies (e.g. 512) and a lot of queued SKBs are sent from the pkt queue. The problem is the number of entries in the pre-allocated sgtable, it is nents = max(rxglom_size, txglom_size) + max(rxglom_size, txglom_size) >> 4 + 1. Given the default [rt]xglom_size=32 it's actually 35 which is too small. Worst case, the pkt queue can end up with 64 SKBs. This occurs when a new SKB is added for each original SKB if tailroom isn't enough to hold tail_pad. At least one sg entry is needed for each SKB. So, eventually the "skb_queue_walk loop" in brcmf_sdiod_sglist_rw may run out of sg entries. This makes sg_next return NULL and this causes the oops. The patch sets nents to max(rxglom_size, txglom_size) * 2 to be able handle the worst-case. Btw. this requires only 64-35=29 * 16 (or 20 if CONFIG_NEED_SG_DMA_LENGTH) = 464 additional bytes of memory.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < 342f87d263462c2670b77ea9a32074cab2ac6fa1342f87d263462c2670b77ea9a32074cab2ac6fa1
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < 7522d7d745d13fbeff3350fe6aa56c8dae2635717522d7d745d13fbeff3350fe6aa56c8dae263571
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < dfb3f9d3f602602de208da7bdcc0f6d5ee74af68dfb3f9d3f602602de208da7bdcc0f6d5ee74af68
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < 67a25ea28f8ec1da8894f2f115d01d3becf67dc767a25ea28f8ec1da8894f2f115d01d3becf67dc7
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < 07c020c6d14d29e5a3ea4e4576b8ecf956a8083407c020c6d14d29e5a3ea4e4576b8ecf956a80834
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < 34941321b516bd7c6103bd01287d71a1804d19d334941321b516bd7c6103bd01287d71a1804d19d3
linuxlinux>= af1fa210f4fc6e304b859b386a3c8a266b1110ab < 857282b819cbaa0675aaab1e7542e2c0579f52d7857282b819cbaa0675aaab1e7542e2c0579f52d7
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 0 < 5.15.0-141.1515.15.0-141.151
linuxlinux_kernel>= 0 < 6.8.0-59.616.8.0-59.61
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.