CVE-2024-57898

LOW

Linux Kernel < 6.12.9 - Use-After-Free in WiFi Link Deletion

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during link delete after clean up Currently, during link deletion, the link ID is first removed from the valid_links bitmap before performing any clean-up operations. However, some functions require the link ID to remain in the valid_links bitmap. One such example is cfg80211_cac_event(). The flow is - nl80211_remove_link() cfg80211_remove_link() ieee80211_del_intf_link() ieee80211_vif_set_links() ieee80211_vif_update_links() ieee80211_link_stop() cfg80211_cac_event() cfg80211_cac_event() requires link ID to be present but it is cleared already in cfg80211_remove_link(). Ultimately, WARN_ON() is hit. Therefore, clear the link ID from the bitmap only after completing the link clean-up.

Scores

CVSS v3 3.3
EPSS 0.0018
EPSS Percentile 7.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (9)
linux/Kernel 6.12.0 - 6.12.9linux
Linux/Linux < 6.12
Linux/Linux 6.12
Linux/Linux 6.12.9 - 6.12.*
Linux/Linux 6.13
Linux/Linux d74380ee99b59a2e46612c12c85e701ab213f4ea - ae07daf440d3220d0986e676317a5da66e4f9dfd
Linux/Linux d74380ee99b59a2e46612c12c85e701ab213f4ea - b5c32ff6a3a38c74facdd1fe34c0d709a55527fd
linux/linux_kernel 6.13 rc1 (2 CPE variants)
linux/linux_kernel < 6.12.9
Published Jan 15, 2025
Tracked Since Feb 18, 2026