7.1

CVE-2024-40929

wifi: iwlwifi: mvm: check n_ssids before accessing the ssids

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: check n_ssids before accessing the ssids

In some versions of cfg80211, the ssids poinet might be a valid one even
though n_ssids is 0. Accessing the pointer in this case will cuase an
out-of-bound access. Fix this by checking n_ssids first.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.17 < 5.10.221
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.162
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.95
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.35
Linux ≫ Linux Kernel Version >= 6.7 < 6.9.6
Linux ≫ Linux Kernel Version 6.10 Update rc1
Linux ≫ Linux Kernel Version 6.10 Update rc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.29
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 2.8 4.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/29a18d56bd64b95bd10bda4afda512558471382a
Patch
https://git.kernel.org/stable/c/3c4771091ea8016c8601399078916f722dd8833b
Patch
https://git.kernel.org/stable/c/60d62757df30b74bf397a2847a6db7385c6ee281
Patch
https://git.kernel.org/stable/c/62e007bdeb91c6879a4652c3426aef1cd9d2937b
Patch
https://git.kernel.org/stable/c/9e719ae3abad60e245ce248ba3f08148f375a614
Patch
https://git.kernel.org/stable/c/f777792952d03bbaf8329fdfa99393a5a33e2640
Patch
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html