PT-2024-29144 · Linux+9 · Linux Kernel+9
Miri Korenblit
·
Published
2024-05-13
·
Updated
2025-09-29
·
CVE-2024-40929
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue arises in the Linux kernel's wifi component, specifically in the iwlwifi module, where the
n ssids value is not properly checked before accessing the ssids pointer. This can lead to an out-of-bound access when n ssids is 0, even if the ssids pointer is valid. The problem is resolved by adding a check for n ssids before accessing the ssids pointer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu