{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-35937", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-05-17T13:50:33.131Z", "datePublished": "2024-05-19T10:10:43.615Z", "dateUpdated": "2026-08-05T11:31:04.899Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:31:04.899Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: check A-MSDU format more carefully\n\nIf it looks like there's another subframe in the A-MSDU\nbut the header isn't fully there, we can end up reading\ndata out of bounds, only to discard later. Make this a\nbit more careful and check if the subframe header can\neven be present." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 8.1, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:A - The malformed A-MSDU is delivered over the air and parsed in the cfg80211/mac80211 receive path, so the attacker must be within radio range of the victim's WiFi interface (or an associated/injecting peer on the same BSS or mesh). Per WiFi frame-injection guidance this is Adjacent.\nAC:L - The attacker fully controls the frame: setting the A-MSDU-present bit and truncating the payload so fewer than 14/15 bytes remain deterministically drives the unchecked skb_copy_bits() and the resulting uninitialized/out-of-bounds header parse, and frames can be replayed indefinitely to groom favorable stack contents.\nPR:N - No credentials or privileges are needed — ieee80211_rx_h_amsdu() only requires an rx->sta entry, which any peer on an open hotspot, open mesh, or a spoofed associated-STA address satisfies, and the parse happens before any payload validation.\nUI:N - The frame is processed automatically by the kernel's WiFi receive path; no action by the device owner or any user is required.\nS:U - The out-of-bounds/uninitialized read and its consequences stay entirely within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The code reads out of bounds / uses uninitialized kernel stack memory, and on the mesh path those 14 bytes are pushed as the Ethernet header of a frame that is delivered up the stack or forwarded back over the air, giving a repeatable kernel-memory disclosure primitive rather than a strictly bounded few-byte read.\nI:N - The defect is purely a read of out-of-bounds/uninitialized memory; all subsequent length computations remain bounds-checked (__ieee80211_amsdu_copy() rejects len > skb->len - offset), so no out-of-bounds write or control-flow corruption primitive is available.\nA:H - An attacker-triggered out-of-bounds read in the WiFi RX softirq path oopses the kernel on hardened/instrumented builds (KASAN/KMSAN, panic_on_warn), and the resulting garbage-derived frame lengths and headers destabilize A-MSDU decapsulation and mesh forwarding, so a remote crash is achievable." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/wireless/util.c" ], "versions": [ { "version": "966d5c2c22edcc0ab3d519af39f91a29329c979a", "lessThan": "9eb3bc0973d084423a6df21cf2c74692ff05647e", "status": "affected", "versionType": "git" }, { "version": "6e4c0d0460bd32ca9244dff3ba2d2da27235de11", "lessThan": "5d7a8585fbb31e88fb2a0f581b70667d3300d1e9", "status": "affected", "versionType": "git" }, { "version": "6e4c0d0460bd32ca9244dff3ba2d2da27235de11", "lessThan": "16da1e1dac23be45ef6e23c41b1508c400e6c544", "status": "affected", "versionType": "git" }, { "version": "6e4c0d0460bd32ca9244dff3ba2d2da27235de11", "lessThan": "9ad7974856926129f190ffbe3beea78460b3b7cc", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/wireless/util.c" ], "versions": [ { "version": "6.3", "status": "affected" }, { "version": "0", "lessThan": "6.3", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.27", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.6", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.6.27" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.8.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.9" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/9eb3bc0973d084423a6df21cf2c74692ff05647e" }, { "url": "https://git.kernel.org/stable/c/5d7a8585fbb31e88fb2a0f581b70667d3300d1e9" }, { "url": "https://git.kernel.org/stable/c/16da1e1dac23be45ef6e23c41b1508c400e6c544" }, { "url": "https://git.kernel.org/stable/c/9ad7974856926129f190ffbe3beea78460b3b7cc" } ], "title": "wifi: cfg80211: check A-MSDU format more carefully", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/5d7a8585fbb31e88fb2a0f581b70667d3300d1e9", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/16da1e1dac23be45ef6e23c41b1508c400e6c544", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/9ad7974856926129f190ffbe3beea78460b3b7cc", "tags": [ "x_transferred" ] }, { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T21:55:02.670Z" } }, { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-35937", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-09-10T15:40:52.262285Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-11T17:33:14.984Z" } } ] } }