CVE-2024-35838
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during connection to an AP MLD), we might remove the station…
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during connection to an AP MLD), we might remove the station without ever marking links valid, and leak them. Fix that.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.22% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/49aaeb8c539b1633b3bd7c2df131ec578aa1eae1Patch
- https://git.kernel.org/stable/c/587c5892976108674bbe61a8ff659de279318034Patch
- https://git.kernel.org/stable/c/b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26Patch
- https://git.kernel.org/stable/c/e04bf59bdba0fa45d52160be676114e16be855a9Patch
- https://git.kernel.org/stable/c/49aaeb8c539b1633b3bd7c2df131ec578aa1eae1Patch
- https://git.kernel.org/stable/c/587c5892976108674bbe61a8ff659de279318034Patch
- https://git.kernel.org/stable/c/b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26Patch
- https://git.kernel.org/stable/c/e04bf59bdba0fa45d52160be676114e16be855a9Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.