CVE-2024-35937

Updated: 2026-02-08 02:01:49.726931

Description:

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to discard later. Make this a bit more careful and check if the subframe header can even be present.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Released CLSA-2025:1759866837 2025-10-08 07:09:50
CentOS 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2025:1761139764 2025-11-10 19:23:06
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Already Fixed 2025-06-11 01:01:34
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Needs Triage 2026-01-16 18:06:42
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Needs Triage 2026-01-17 02:47:33
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2025:1763722365 2026-01-27 08:07:47
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH Ignored 2025-09-23 10:52:26 Postponed until request or high risk detected
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Ignored 2025-09-23 10:52:23 Postponed until request or high risk detected
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2025:1761074747 2025-10-21 22:00:05
Oracle Linux 7 ELS kernel 3.10.0 7.1 HIGH Already Fixed 2025-06-11 01:00:19
Total: 15