CVE-2024-50235

HIGH EPSS 15.4%
Published Nov 9, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Nov 9, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear wdev->cqm_config pointer on free When we free wdev->cqm_config when unregistering, we also need to clear out the pointer since the same wdev/netdev may get re-registered in another network namespace, then destroyed later, running this code again, which results in a double-free.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
15.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-415

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥6.1.57  –  <6.1.116
linuxlinux_kernel*≥6.5.7  –  <6.6
linuxlinux_kernel*≥6.6  –  <6.6.60
linuxlinux_kernel*≥6.7  –  <6.11.7
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/64e4c45d23cd7f6167f69cc2d2877bc7f54292e5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6c44abb2d4c3262737d5d67832daebc8cf48b8c9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ba392e1355ba74b1d4fa11b85f71ab6ed7ecc058
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d5fee261dfd9e17b08b1df8471ac5d5736070917
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/64e4c45d23cd7f6167f69cc2d2877bc7f54292e5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6c44abb2d4c3262737d5d67832daebc8cf48b8c9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ba392e1355ba74b1d4fa11b85f71ab6ed7ecc058
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d5fee261dfd9e17b08b1df8471ac5d5736070917
    Patch