CVE-2024-46825

MEDIUM

Linux Kernel - Denial of Service via Firmware Link ID Check

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check The lookup function iwl_mvm_rcu_fw_link_id_to_link_conf() is normally called with input from the firmware, so it should use IWL_FW_CHECK() instead of WARN_ON().

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 14.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (11)
linux/Kernel 6.5.0 - 6.6.51linux
linux/Kernel 6.7.0 - 6.10.10linux
Linux/Linux < 6.5
Linux/Linux 6.10.10 - 6.10.*
Linux/Linux 6.11
Linux/Linux 6.5
Linux/Linux 6.6.51 - 6.6.*
Linux/Linux d464550bb2e9cce2c377ed39c7e327e7db6e2be9 - 3cca098c91391b3fa48142bfda57048b985c87f6
Linux/Linux d464550bb2e9cce2c377ed39c7e327e7db6e2be9 - 415f3634d53c7fb4cf07d2f5a0be7f2e15e6da33
Linux/Linux d464550bb2e9cce2c377ed39c7e327e7db6e2be9 - 9215152677d4b321801a92b06f6d5248b2b4465f
... and 1 more
Published Sep 27, 2024
Tracked Since Feb 18, 2026