CVE-2024-57898

LOW EPSS 7.8%
Published Jan 15, 20251y ago · Modified Jun 17, 20261w ago
3.3 CVSS 3.1
Low
Find Similar
Published Jan 15, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during link delete after clean up Currently, during link deletion, the link ID is first removed from the valid_links bitmap before performing any clean-up operations. However, some functions require the link ID to remain in the valid_links bitmap. One such example is cfg80211_cac_event(). The flow is - nl80211_remove_link() cfg80211_remove_link() ieee80211_del_intf_link() ieee80211_vif_set_links() ieee80211_vif_update_links() ieee80211_link_stop() cfg80211_cac_event() cfg80211_cac_event() requires link ID to be present but it is cleared already in cfg80211_remove_link(). Ultimately, WARN_ON() is hit. Therefore, clear the link ID from the bitmap only after completing the link clean-up.

CVSS Details

Base Score
3.3
Exploitability
1.8
Impact
1.4
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
7.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 3

VendorProductVersionRange
linuxlinux_kernel* <6.12.9
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any

References 2

  • git.kernel.org https://git.kernel.org/stable/c/ae07daf440d3220d0986e676317a5da66e4f9dfd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b5c32ff6a3a38c74facdd1fe34c0d709a55527fd
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/ae07daf440d3220d0986e676317a5da66e4f9dfd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b5c32ff6a3a38c74facdd1fe34c0d709a55527fd
    Patch