CVE-2024-58015
published 2025-02-27CVE-2024-58015: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix for out-of bound access error Selfgen stats are placed in a buffer using…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Fix for out-of bound access error
Selfgen stats are placed in a buffer using print_array_to_buf_index() function.
Array length parameter passed to the function is too big, resulting in possible
out-of bound memory error.
Decreasing buffer size by one fixes faulty upper bound of passed array.
Discovered in coverity scan, CID 1600742 and CID 1600758
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.16.3-1 (forky) | linux 6.16.3-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 8700c4bf8b7ed98037d2acf1eaf770ad6dd431d4 | 8700c4bf8b7ed98037d2acf1eaf770ad6dd431d4 |
| linux | linux | >= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < eb8c0534713865d190856f10bfc97cf0b88475b1 | eb8c0534713865d190856f10bfc97cf0b88475b1 |
| linux | linux_kernel | >= 0 < 6.16.3-1 | 6.16.3-1 |
| linux | linux_kernel | >= 6.3 < 6.13.3 | 6.13.3 |
| msrc | azl3_kernel_6.6.92.2-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
vendor_msrc6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: ath12k: Fix for out-of bound access error
vendor_redhat·2025-02-27·CVSS 7.1
CVE-2024-58015 [HIGH] CWE-125 kernel: wifi: ath12k: Fix for out-of bound access error
kernel: wifi: ath12k: Fix for out-of bound access error
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Fix for out-of bound access error
Selfgen stats are placed in a buffer using print_array_to_buf_index() function.
Array length parameter passed to the function is too big, resulting in possible
out-of bound memory error.
Decreasing buffer size by one fixes faulty upper bound of passed array.
Discovered in coverity scan, CID 1600742 and CID 1600758
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Microsoft
wifi: ath12k: Fix for out-of bound access error
vendor_msrc·2025-02-11·CVSS 6.0
CVE-2024-58015 [HIGH] wifi: ath12k: Fix for out-of bound access error
wifi: ath12k: Fix for out-of bound access error
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2024-58015: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12...
vendor_debian·2024·CVSS 7.1
CVE-2024-58015 [HIGH] CVE-2024-58015: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix for out-of bound access error Selfgen stats are placed in a buffer using print_array_to_buf_index() function. Array length parameter passed to the function is too big, resulting in possible out-of bound memory error. Decreasing buffer size by one fixes faulty upper bound of passed array. Discovered in coverity scan, CID 1600742 and CID 1600758
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.16.3-1)
sid: resolved (fixed in 6.16.3-1)
trixie: open
VulDB
Linux Kernel up to 6.13.2 print_array_to_buf_index length out-of-bounds (EUVD-2025-5195 / Nessus ID 274839)
vuldb·2026-05-25·CVSS 7.1
CVE-2024-58015 [HIGH] Linux Kernel up to 6.13.2 print_array_to_buf_index length out-of-bounds (EUVD-2025-5195 / Nessus ID 274839)
A vulnerability was found in Linux Kernel up to 6.13.2. It has been declared as problematic. Affected by this vulnerability is the function print_array_to_buf_index. The manipulation of the argument length results in out-of-bounds read.
This vulnerability is known as CVE-2024-58015. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
OSV
CVE-2024-58015: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix for out-of bound access error Selfgen stats are placed in a buff
osv·2025-02-27·CVSS 7.1
CVE-2024-58015 [HIGH] CVE-2024-58015: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix for out-of bound access error Selfgen stats are placed in a buff
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix for out-of bound access error Selfgen stats are placed in a buffer using print_array_to_buf_index() function. Array length parameter passed to the function is too big, resulting in possible out-of bound memory error. Decreasing buffer size by one fixes faulty upper bound of passed array. Discovered in coverity scan, CID 1600742 and CID 1600758
GHSA
GHSA-wgxf-r68r-7w9h: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Fix for out-of bound access error
Selfgen stats are placed in a bu
ghsa_unreviewed·2025-02-27
CVE-2024-58015 [HIGH] CWE-125 GHSA-wgxf-r68r-7w9h: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Fix for out-of bound access error
Selfgen stats are placed in a bu
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Fix for out-of bound access error
Selfgen stats are placed in a buffer using print_array_to_buf_index() function.
Array length parameter passed to the function is too big, resulting in possible
out-of bound memory error.
Decreasing buffer size by one fixes faulty upper bound of passed array.
Discovered in coverity scan, CID 1600742 and CID 1600758
No detection rules found.
No public exploits indexed.
2025-02-27
Published