PT-2024-32175 · Linux+5 · Linux Kernel+5

Marcin Ślusarz

·

Published

2024-05-28

·

Updated

2026-03-14

·

CVE-2024-46760

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the rtw rx fill rx status function on the hw object and/or its fields. This occurs because the initialization routine can start getting USB replies before rtw dev is fully set up. The stack trace includes functions such as rtw rx fill rx status, rtw8821c query rx desc, rtw usb rx handler, and others. The problem can be fixed by moving the first usb submit urb after everything is set up.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13260
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-49557
BDU:2025-05917
CVE-2024-46760
ECHO-32B7-1A87-CA73
MGASA-2024-0316
MGASA-2024-0318
OESA-2024-2219
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
SUSE-SU-2024:3551-1
SUSE-SU-2024:3553-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu