CVE-2024-38562
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: Avoid address calculations via out of bounds array indexing Before request->channels[] can be used, request->n_channels must be set.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: Avoid address calculations via out of bounds array indexing Before request->channels[] can be used, request->n_channels must be set. Additionally, address calculations for memory after the "channels" array need to be calculated from the allocation base ("request") rather than via the first "out of bounds" index of "channels", otherwise run-time bounds checking will throw a warning.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-129
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/4e2a5566462b53db7d4c4722da86eedf0b8f546cPatch
- https://git.kernel.org/stable/c/838c7b8f1f278404d9d684c34a8cb26dc41aaaa1Patch
- https://git.kernel.org/stable/c/8fa4d56564ee7cc2ee348258d88efe191d70dd7fPatch
- https://git.kernel.org/stable/c/ed74398642fcb19f6ff385c35a7d512c6663e17bPatch
- https://git.kernel.org/stable/c/4e2a5566462b53db7d4c4722da86eedf0b8f546cPatch
- https://git.kernel.org/stable/c/838c7b8f1f278404d9d684c34a8cb26dc41aaaa1Patch
- https://git.kernel.org/stable/c/8fa4d56564ee7cc2ee348258d88efe191d70dd7fPatch
- https://git.kernel.org/stable/c/ed74398642fcb19f6ff385c35a7d512c6663e17bPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.