CVE-2024-26683
Last modified
CVE-2024-26683 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: detect stuck ECSA element in probe resp We recently added some validation that we don't try to connect to an AP that is currently in a channel switch process, since that might want the channel to be quiet or we might not be able to connect in time to hear the switching in a beacon. This was in commit c09c4f31998b ("wifi: mac80211: don't connect to an AP while it's in a CSA process"). However, we promptly got a report that this caused new connection failures, and it turns out that the AP that we now cannot connect to is permanently advertising an extended channel switch announcement, even with quiet. The AP in question was an Asus RT-AC53, with firmware 3.0.0.4.380_10760-g21a5898. As a first step, attempt to detect that we're dealing with such a situation, so mac80211 can use this later.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: detect stuck ECSA element in probe resp We recently added some validation that we don't try to connect to an AP that is currently in a channel switch process, since that might want the channel to be quiet or we might not be able to connect in time to hear the switching in a beacon. This was in commit c09c4f31998b ("wifi: mac80211: don't connect to an AP while it's in a CSA process"). However, we promptly got a report that this caused new connection failures, and it turns out that the AP that we now cannot connect to is permanently advertising an extended channel switch announcement, even with quiet. The AP in question was an Asus RT-AC53, with firmware 3.0.0.4.380_10760-g21a5898. As a first step, attempt to detect that we're dealing with such a situation, so mac80211 can use this later.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 6.7, < 6.7.5 | — |
| Linux | Linux Kernel | 6.8 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-26683?
How severe is CVE-2024-26683?
How do I fix CVE-2024-26683?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-26678In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26679In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-2668A vulnerability has been found in Campcodes Online Job Finde…6.5
- CVE-2024-26680In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26681In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26682In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26684In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26685In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26686In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26687In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26688In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26689In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2024-26683?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
