Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-27410— wifi: nl80211: reject iftype change with mesh ID change

CVSS 7.8 · High EPSS 0.26% · P17

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux7b0a0e3c3a88260b6fcb017e49f198463aa62ed1< 930e826962d9f01dcd2220176134427358d112f2affected
7b0a0e3c3a88260b6fcb017e49f198463aa62ed1< 177d574be4b58f832354ab1ef5a297aa0c9aa2dfaffected
7b0a0e3c3a88260b6fcb017e49f198463aa62ed1< a2add961a5ed25cfd6a74f9ffb9e7ab6d6ded838affected
7b0a0e3c3a88260b6fcb017e49f198463aa62ed1< f78c1375339a291cba492a70eaf12ec501d28a8eaffected
7a53ad13c09150076b7ddde96c2dfc5622c90b45affected
5.19.2< 5.20affected
6.0affected
< 6.0unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-27410

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: nl80211: reject iftype change with mesh ID change
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't yet in mesh mode, at the same time as changing it into mesh mode. This leads to an overwrite of data in the wdev->u union for the interface type it currently has, causing cfg80211_change_iface() to do wrong things when switching. We could probably allow setting an interface to mesh while setting the mesh ID at the same time by doing a different order of operations here, but realistically there's no userspace that's going to do this, so just disallow changes in iftype when setting mesh ID.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 wifi 模块 cfg80211_change_iface 方法在执行切换时存在错误。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 7b0a0e3c3a88260b6fcb017e49f198463aa62ed1 ~ 930e826962d9f01dcd2220176134427358d112f2 -
LinuxLinux 6.0 -

II. Public POCs for CVE-2024-27410

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-27410

登录查看更多情报信息。

Mailing List Discussions for CVE-2024-27410 (2)

Other References for CVE-2024-27410 (7)

Same Patch Batch · Linux · 2024-05-17 · 135 CVEs total

CVE-2023-526879.8 CRITICALcrypto: safexcel - Add error handling for dma_map_sg() calls
CVE-2024-358568.8 HIGHBluetooth: btusb: mediatek: Fix double free of skb in coredump
CVE-2024-358048.8 HIGHKVM: x86: Mark target gfn of emulated atomic instruction as dirty
CVE-2024-358438.8 HIGHiommu/vt-d: Use device rbtree in iopf reporting path
CVE-2024-358118.8 HIGHwifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach
CVE-2024-274158.8 HIGHnetfilter: bridge: confirm multicast packets before passing them up the stack
CVE-2024-274168.8 HIGHBluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST
CVE-2024-274048.2 HIGHmptcp: fix data races on remote_id
CVE-2023-526698.2 HIGHcrypto: s390/aes - Fix buffer overread in CTR mode
CVE-2024-358348.2 HIGHxsk: recycle buffer in case Rx queue was full
CVE-2024-357898.0 HIGHwifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes
CVE-2024-358307.8 HIGHmedia: tc358743: register v4l2 async device only after successful setup
CVE-2024-358357.8 HIGHnet/mlx5e: fix a double-free in arfs_create_groups
CVE-2024-358277.8 HIGHio_uring/net: fix overflow check in io_recvmsg_mshot_prep()
CVE-2023-526627.8 HIGHdrm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node
CVE-2024-358177.8 HIGHdrm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag
CVE-2024-358087.8 HIGHmd/dm-raid: don't call md_reap_sync_thread() directly
CVE-2024-357937.8 HIGHdebugfs: fix wait/cancellation handling during remove
CVE-2024-357987.8 HIGHbtrfs: fix race in read_extent_buffer_pages()
CVE-2024-358147.8 HIGHswiotlb: Fix double-allocation of slots due to broken alignment handling

Showing top 20 of 135 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-27410

No comments yet


Leave a comment