PT-2024-33770 · Linux+8 · Linux Kernel+8

Miri Korenblit

·

Published

2024-10-21

·

Updated

2026-05-26

·

CVE-2024-49929

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.58
Description: A NULL pointer dereference issue has been resolved in the Linux kernel. The issue occurs in the iwl mvm tx skb sta() and iwl mvm tx mpdu() functions, which verify that the mvmvsta pointer is not NULL. The pointer is retrieved using iwl mvm sta from mac80211, which dereferences the ieee80211 sta pointer. If the sta pointer is NULL, iwl mvm sta from mac80211 will dereference a NULL pointer. The fix involves checking the sta pointer before retrieving the mvmsta from it.
Recommendations: For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider implementing checks to prevent NULL pointer dereferences in the affected functions. Restrict access to the vulnerable iwl mvm tx skb sta() and iwl mvm tx mpdu() functions to minimize the risk of exploitation. Avoid using the sta pointer in the affected code paths until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-14046
AZL-51419
BDU:2025-07994
CVE-2024-49929
DLA-4076-1
INFSA-2025_6966
MGASA-2024-0344
MGASA-2024-0345
OESA-2024-2491
OESA-2024-2493
OESA-2024-2494
OESA-2024-2522
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_3986-1
OPENSUSE-SU-2025:14705-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4100-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:0034-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7301-1
USN-7303-1
USN-7303-2
USN-7303-3
USN-7304-1
USN-7310-1
USN-7311-1
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7468-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu