PT-2024-21460 · Linux+1 · Linux Kernel+1
Coldolt
·
Published
2024-04-02
·
Updated
2025-02-03
·
CVE-2024-26682
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions <= 6.7.4
Description
The issue is related to the wifi mac80211 component in the Linux kernel, where some access points (APs) have ECSA elements stuck in their probe response. This causes the kernel to not attempt to connect while CSA is happening, resulting in a failure to connect to such APs. The situation is improved by checking more carefully and ignoring the ECSA if cfg80211 has previously detected the ECSA element being stuck in the probe response. Additionally, connecting to an AP that's switching to a channel it's already using is allowed, unless it's using quiet mode.
Recommendations
To resolve the issue, upgrade the Linux kernel to a version higher than 6.7.4.
As a temporary workaround, consider restricting access to APs with stuck ECSA elements in their probe response until a patch is available.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Suse