PT-2024-36842 · Linux+6 · Linux Kernel+6
Published
2024-12-27
·
Updated
2025-05-28
·
CVE-2024-56539
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been resolved in the Linux kernel related to the wifi mwifiex driver. The issue was caused by a memcpy field-spanning write warning in the mwifiex config scan function. This warning occurred when the size of the SSID of the network the device was connected to exceeded the expected size, resulting in a field-spanning write. The source of the warning is in the scan.c file at line 904, where the ssid len is assigned and then used in a memcpy operation. The fix involves replacing a one-element array with a flexible-array member in the struct mwifiex ie types wildcard ssid params.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu