CVE-2024-32913

CRITICAL

Android - Remote Code Execution via Integer Overflow in wl_notify_rx_mgmt_frame

Title source: llm
STIX 2.1

Description

In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0334
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-190 CWE-787
Status published
Products (1)
google/android
Published Jun 13, 2024
Tracked Since Feb 18, 2026