CVE-2024-35937

Updated: 2025-03-10 21:35:42.661508

Description:

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to discard later. Make this a bit more careful and check if the subframe header can even be present.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.1000000000000005

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Ignored 2024-08-13 14:25:18
CentOS 6 ELS kernel 2.6.32 7.1 HIGH Ignored 2024-08-13 14:25:18
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Already Fixed 2025-06-11 01:01:34
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Ignored 2024-08-20 05:26:13
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Ignored 2024-08-20 05:26:13
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Ignored 2024-08-20 05:26:13
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH Ignored 2024-08-13 14:25:18
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Ignored 2024-08-13 14:25:18
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Ignored 2024-08-13 14:25:18
Oracle Linux 7 ELS kernel 3.10.0 7.1 HIGH Already Fixed 2025-06-11 01:00:19
Total: 14