CVE-2024-26637 (GCVE-0-2024-26637)
Vulnerability from cvelistv5
Published
2024-03-18 10:14
Modified
2026-08-05 11:26
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: rely on mac80211 debugfs handling for vif mac80211 started to delete debugfs entries in certain cases, causing a ath11k to crash when it tried to delete the entries later. Fix this by relying on mac80211 to delete the entries when appropriate and adding them from the vif_add_debugfs handler.
Impacted products
Vendor Product Version
Linux Linux Version: 0a3d898ee9a8303d5b3982b97ef0703919c3ea76
Version: 0a3d898ee9a8303d5b3982b97ef0703919c3ea76
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:07:19.812Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/aa74ce30a8a40d19a4256de4ae5322e71344a274"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/556857aa1d0855aba02b1c63bc52b91ec63fc2cc"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26637",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:55:06.774541Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:16.633Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/core.h",
            "drivers/net/wireless/ath/ath11k/debugfs.c",
            "drivers/net/wireless/ath/ath11k/debugfs.h",
            "drivers/net/wireless/ath/ath11k/mac.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "aa74ce30a8a40d19a4256de4ae5322e71344a274",
              "status": "affected",
              "version": "0a3d898ee9a8303d5b3982b97ef0703919c3ea76",
              "versionType": "git"
            },
            {
              "lessThan": "556857aa1d0855aba02b1c63bc52b91ec63fc2cc",
              "status": "affected",
              "version": "0a3d898ee9a8303d5b3982b97ef0703919c3ea76",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/core.h",
            "drivers/net/wireless/ath/ath11k/debugfs.c",
            "drivers/net/wireless/ath/ath11k/debugfs.h",
            "drivers/net/wireless/ath/ath11k/mac.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "lessThan": "6.7",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.3",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: rely on mac80211 debugfs handling for vif\n\nmac80211 started to delete debugfs entries in certain cases, causing a\nath11k to crash when it tried to delete the entries later. Fix this by\nrelying on mac80211 to delete the entries when appropriate and adding\nthem from the vif_add_debugfs handler."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The stale-dentry free is reached only through local control-plane operations on the wireless netdev \u2014 rtnetlink/nl80211 interface down or delete, MAC/iftype change, or a local system-suspend request \u2014 not from any received 802.11 frame or network packet. No remote or adjacent peer can drive `drv_remove_interface()`.\nAC:L - The failure is deterministic, not a race: once mac80211\u0027s `ieee80211_debugfs_recreate_netdev()` has dput the \"twt\" dentry, ath11k\u0027s very next `debugfs_remove_recursive(arvif-\u003edebugfs_twt)` in the same `drv_remove_interface()` call always operates on freed memory. The attacker needs no specific timing and can pre-shape the dentry slab at leisure before triggering.\nPR:L - `__ieee80211_suspend()` (net/mac80211/pm.c:164) tears every running vif out of the driver whenever WoWLAN is not armed, and suspend is routinely available to an ordinary logged-in local user via systemd-logind/polkit or lid close on ath11k-equipped laptops; the equivalent hotspot-toggle teardown is user-accessible on Android. No CAP_NET_ADMIN is strictly required for that route, so the unprivileged-local case is the correct, higher-severity reading.\nUI:N - The attacker performs the triggering action (suspend request or interface teardown) directly; no separate victim needs to be induced into doing anything.\nS:U - The corruption is confined to kernel memory within the same security authority \u2014 a driver debugfs dentry and whatever kernel slab object reclaims it. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free on a freed dentry that debugfs then walks (`d_inode`, `d_subdirs`, `d_fsdata`); if the slab object is reclaimed by a sprayed dentry, `remove_one()`/`__debugfs_file_removed()` dereference attacker-influenced pointers, yielding an arbitrary-read primitive rather than a bounded leak.\nI:H - `simple_recursive_removal()` opens with `dget()`, a lockref write into freed memory, and then `d_invalidate()`/`dput()`s an entire subtree reachable from the reclaimed object \u2014 corrupting refcounts on live filesystem dentries and inodes, which is a standard route to a controlled write and control-flow hijack.\nA:H - Every affected interface teardown reliably oopses the kernel (dereferencing a freed dentry\u0027s `d_inode` under `inode_lock()`), and the underflowing `simple_release_fs()` mount count compounds it; a use-after-free of this kind crashes the machine even when not further exploited."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:26:26.884Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/aa74ce30a8a40d19a4256de4ae5322e71344a274"
        },
        {
          "url": "https://git.kernel.org/stable/c/556857aa1d0855aba02b1c63bc52b91ec63fc2cc"
        }
      ],
      "title": "wifi: ath11k: rely on mac80211 debugfs handling for vif",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26637",
    "datePublished": "2024-03-18T10:14:48.378Z",
    "dateReserved": "2024-02-19T14:20:24.137Z",
    "dateUpdated": "2026-08-05T11:26:26.884Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/aa74ce30a8a40d19a4256de4ae5322e71344a274\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/556857aa1d0855aba02b1c63bc52b91ec63fc2cc\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:07:19.812Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26637\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:55:06.774541Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:15.879Z\"}}], \"cna\": {\"title\": \"wifi: ath11k: rely on mac80211 debugfs handling for vif\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The stale-dentry free is reached only through local control-plane operations on the wireless netdev \\u2014 rtnetlink/nl80211 interface down or delete, MAC/iftype change, or a local system-suspend request \\u2014 not from any received 802.11 frame or network packet. No remote or adjacent peer can drive `drv_remove_interface()`.\\nAC:L - The failure is deterministic, not a race: once mac80211\u0027s `ieee80211_debugfs_recreate_netdev()` has dput the \\\"twt\\\" dentry, ath11k\u0027s very next `debugfs_remove_recursive(arvif-\u003edebugfs_twt)` in the same `drv_remove_interface()` call always operates on freed memory. The attacker needs no specific timing and can pre-shape the dentry slab at leisure before triggering.\\nPR:L - `__ieee80211_suspend()` (net/mac80211/pm.c:164) tears every running vif out of the driver whenever WoWLAN is not armed, and suspend is routinely available to an ordinary logged-in local user via systemd-logind/polkit or lid close on ath11k-equipped laptops; the equivalent hotspot-toggle teardown is user-accessible on Android. No CAP_NET_ADMIN is strictly required for that route, so the unprivileged-local case is the correct, higher-severity reading.\\nUI:N - The attacker performs the triggering action (suspend request or interface teardown) directly; no separate victim needs to be induced into doing anything.\\nS:U - The corruption is confined to kernel memory within the same security authority \\u2014 a driver debugfs dentry and whatever kernel slab object reclaims it. No VM, IOMMU, or sandbox boundary is crossed.\\nC:H - This is a use-after-free on a freed dentry that debugfs then walks (`d_inode`, `d_subdirs`, `d_fsdata`); if the slab object is reclaimed by a sprayed dentry, `remove_one()`/`__debugfs_file_removed()` dereference attacker-influenced pointers, yielding an arbitrary-read primitive rather than a bounded leak.\\nI:H - `simple_recursive_removal()` opens with `dget()`, a lockref write into freed memory, and then `d_invalidate()`/`dput()`s an entire subtree reachable from the reclaimed object \\u2014 corrupting refcounts on live filesystem dentries and inodes, which is a standard route to a controlled write and control-flow hijack.\\nA:H - Every affected interface teardown reliably oopses the kernel (dereferencing a freed dentry\u0027s `d_inode` under `inode_lock()`), and the underflowing `simple_release_fs()` mount count compounds it; a use-after-free of this kind crashes the machine even when not further exploited.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"0a3d898ee9a8303d5b3982b97ef0703919c3ea76\", \"lessThan\": \"aa74ce30a8a40d19a4256de4ae5322e71344a274\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0a3d898ee9a8303d5b3982b97ef0703919c3ea76\", \"lessThan\": \"556857aa1d0855aba02b1c63bc52b91ec63fc2cc\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/wireless/ath/ath11k/core.h\", \"drivers/net/wireless/ath/ath11k/debugfs.c\", \"drivers/net/wireless/ath/ath11k/debugfs.h\", \"drivers/net/wireless/ath/ath11k/mac.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.7\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.7\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.7.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/wireless/ath/ath11k/core.h\", \"drivers/net/wireless/ath/ath11k/debugfs.c\", \"drivers/net/wireless/ath/ath11k/debugfs.h\", \"drivers/net/wireless/ath/ath11k/mac.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/aa74ce30a8a40d19a4256de4ae5322e71344a274\"}, {\"url\": \"https://git.kernel.org/stable/c/556857aa1d0855aba02b1c63bc52b91ec63fc2cc\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nwifi: ath11k: rely on mac80211 debugfs handling for vif\\n\\nmac80211 started to delete debugfs entries in certain cases, causing a\\nath11k to crash when it tried to delete the entries later. Fix this by\\nrelying on mac80211 to delete the entries when appropriate and adding\\nthem from the vif_add_debugfs handler.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.3\", \"versionStartIncluding\": \"6.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"6.7\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:26:26.884Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26637\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:26:26.884Z\", \"dateReserved\": \"2024-02-19T14:20:24.137Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-03-18T10:14:48.378Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…