PT-2024-8303 · Linux+5 · Linux Kernel+5

Alexis Lothoré

·

Published

2024-01-12

·

Updated

2025-02-03

·

CVE-2024-27053

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.7.0-rc1-wt+
Description The issue arises from incorrect RCU usage in the connect path of the wifi component, specifically in the wilc parse join bss param() function. When lockdep is enabled, calls to the connect function from the cfg802.11 layer lead to a warning about suspicious RCU usage. This warning is emitted because the code dereferences an RCU pointer without being in an RCU critical section. The fix involves moving the RCU dereference to a RCU read critical section to avoid this issue.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the RCU usage in the connect path. Specifically, versions 6.7.0-rc1-wt and later should include this fix. If updating is not immediately possible, consider applying the patch that moves the RCU dereference to a RCU read critical section manually. However, this should be done with caution and only by experienced developers or system administrators.
At the moment, there is no information about other workarounds or mitigation measures for this specific issue.

Exploit

Fix

DoS

NULL Pointer Dereference

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09856
CVE-2024-27053
DLA-3842-1
DSA-5681-1
OESA-2024-1765
OESA-2024-1768
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6871-1
USN-6878-1
USN-6892-1
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6919-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu