CVE-2024-47738

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/10/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: mac80211: don&amp;#39;t use rate mask for offchannel TX either<br /> <br /> Like the commit ab9177d83c04 ("wifi: mac80211: don&amp;#39;t use rate mask for<br /> scanning"), ignore incorrect settings to avoid no supported rate warning<br /> reported by syzbot.<br /> <br /> The syzbot did bisect and found cause is commit 9df66d5b9f45 ("cfg80211:<br /> fix default HE tx bitrate mask in 2G band"), which however corrects<br /> bitmask of HE MCS and recognizes correctly settings of empty legacy rate<br /> plus HE MCS rate instead of returning -EINVAL.<br /> <br /> As suggestions [1], follow the change of SCAN TX to consider this case of<br /> offchannel TX as well.<br /> <br /> [1] https://lore.kernel.org/linux-wireless/6ab2dc9c3afe753ca6fdcdd1421e7a1f47e87b84.camel@sipsolutions.net/T/#m2ac2a6d2be06a37c9c47a3d8a44b4f647ed4f024

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.51 (including) 5.11 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.12.18 (including) 5.13 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.13.3 (including) 5.14 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.14 (including) 6.1.113 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.54 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.10.13 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.11 (including) 6.11.2 (excluding)