CVE-2024-41072
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: wext: add extra SIOCSIWSCAN data check In 'cfg80211_wext_siwscan()', add extra check whether number of channels passed via 'ioctl(sock, SIOCSIWSCAN, ...)' doesn't exceed…
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: wext: add extra SIOCSIWSCAN data check In 'cfg80211_wext_siwscan()', add extra check whether number of channels passed via 'ioctl(sock, SIOCSIWSCAN, ...)' doesn't exceed IW_MAX_FREQUENCIES and reject invalid request with -EINVAL otherwise.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/001120ff0c9e3557dee9b5ee0d358e0fc189996fPatch
- https://git.kernel.org/stable/c/35cee10ccaee5bd451a480521bbc25dc9f07fa5bPatch
- https://git.kernel.org/stable/c/6295bad58f988eaafcf0e6f8b198a580398acb3bPatch
- https://git.kernel.org/stable/c/6ef09cdc5ba0f93826c09d810c141a8d103a80fcPatch
- https://git.kernel.org/stable/c/a43cc0558530b6c065976b6b9246f512f8d3593bPatch
- https://git.kernel.org/stable/c/b02ba9a0b55b762bd04743a22f3d9f9645005e79Patch
- https://git.kernel.org/stable/c/de5fcf757e33596eed32de170ce5a93fa44dd2acPatch
- https://git.kernel.org/stable/c/fe9644efd86704afe50e56b64b609de340ab7c95Patch
- https://git.kernel.org/stable/c/001120ff0c9e3557dee9b5ee0d358e0fc189996fPatch
- https://git.kernel.org/stable/c/35cee10ccaee5bd451a480521bbc25dc9f07fa5bPatch
- https://git.kernel.org/stable/c/6295bad58f988eaafcf0e6f8b198a580398acb3bPatch
- https://git.kernel.org/stable/c/6ef09cdc5ba0f93826c09d810c141a8d103a80fcPatch
- https://git.kernel.org/stable/c/a43cc0558530b6c065976b6b9246f512f8d3593bPatch
- https://git.kernel.org/stable/c/b02ba9a0b55b762bd04743a22f3d9f9645005e79Patch
- https://git.kernel.org/stable/c/de5fcf757e33596eed32de170ce5a93fa44dd2acPatch
- https://git.kernel.org/stable/c/fe9644efd86704afe50e56b64b609de340ab7c95Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.