CVE-2024-43841

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/08/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: virt_wifi: avoid reporting connection success with wrong SSID<br /> <br /> When user issues a connection with a different SSID than the one<br /> virt_wifi has advertised, the __cfg80211_connect_result() will<br /> trigger the warning: WARN_ON(bss_not_found).<br /> <br /> The issue is because the connection code in virt_wifi does not<br /> check the SSID from user space (it only checks the BSSID), and<br /> virt_wifi will call cfg80211_connect_result() with WLAN_STATUS_SUCCESS<br /> even if the SSID is different from the one virt_wifi has advertised.<br /> Eventually cfg80211 won&amp;#39;t be able to find the cfg80211_bss and generate<br /> the warning.<br /> <br /> Fixed it by checking the SSID (from user space) in the connection code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.0 (including) 6.1.103 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.44 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.10.3 (excluding)