CVE-2024-35937

🟡 Monitoruj

Błąd w kernelu Linux w obsłudze A-MSDU może prowadzić do odczytu danych poza przydzielonym zakresem.

CVSS
8.1
EPSS
0.3%
Exploit
none
Vendor
linux
Opis źródłowy (NVD)

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to discard later. Make this a bit more careful and check if the subframe header can even be present.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2024-05-19 11:15:49 UTC
Ostatnia modyfikacja (NVD)2026-10-08 18:21:56 UTC
Referencje