CVE-2024-26897
Last modified
CVE-2024-26897 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete The ath9k_wmi_event_tasklet() used in ath9k_htc assumes that all the data structures have been fully initialised by the time it runs. However, because of the order in which things are initialised, this is not guaranteed to be the case, because the device is exposed to the USB subsystem before the ath9k driver initialisation is completed. We already committed a partial fix for this in commit: 8b3046abc99e ("ath9k_htc: fix NULL pointer dereference at ath9k_htc_tx_get_packet()") However, that commit only aborted the WMI_TXSTATUS_EVENTID command in the event tasklet, pairing it with an "initialisation complete" bit in the TX struct. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete The ath9k_wmi_event_tasklet() used in ath9k_htc assumes that all the data structures have been fully initialised by the time it runs. However, because of the order in which things are initialised, this is not guaranteed to be the case, because the device is exposed to the USB subsystem before the ath9k driver initialisation is completed. We already committed a partial fix for this in commit: 8b3046abc99e ("ath9k_htc: fix NULL pointer dereference at ath9k_htc_tx_get_packet()") However, that commit only aborted the WMI_TXSTATUS_EVENTID command in the event tasklet, pairing it with an "initialisation complete" bit in the TX struct. It seems syzbot managed to trigger the race for one of the other commands as well, so let's just move the existing synchronisation bit to cover the whole tasklet (setting it at the end of ath9k_htc_probe_device() instead of inside ath9k_tx_init()).
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.10.136, < 5.10.214 |
| Linux | Linux Kernel | >= 5.15.17, < 5.15.153 |
| Linux | Linux Kernel | >= 5.16.3, < 6.1.83 |
| Linux | Linux Kernel | >= 6.2, < 6.6.23 |
| Linux | Linux Kernel | >= 6.7, < 6.7.11 |
| Linux | Linux Kernel | >= 6.8, < 6.8.2 |
| Debian | Debian Linux | 10.0 |
References
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-26897?
How severe is CVE-2024-26897?
How do I fix CVE-2024-26897?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-26891In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26892In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-26893In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26894In the Linux kernel, the following vulnerability has been re…6
- CVE-2024-26895In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-26896In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26898In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-26899In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-2690A vulnerability was found in SourceCodester Online Discussio…9.8
- CVE-2024-26900In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26901In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-26902In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2024-26897?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
