CVE-2024-35789 (GCVE-0-2024-35789)
Vulnerability from cvelistv5
Published
2024-05-17 12:24
Modified
2026-08-05 11:29
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's netdev, which can cause use-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx after the VLAN change.
Impacted products
Vendor Product Version
Linux Linux Version: a7f1721684628b8ae6015bca9a176046ee6f30cc
Version: bd7e90c82850f49c23004d54de14e46d373748a6
Version: cc413b375c6d95e68a4629cb1ba9d099de78ebb9
Version: dd0b45538146cb6a54d6da7663b8c3afd16ebcfd
Version: dd0b45538146cb6a54d6da7663b8c3afd16ebcfd
Version: dd0b45538146cb6a54d6da7663b8c3afd16ebcfd
Version: dd0b45538146cb6a54d6da7663b8c3afd16ebcfd
Version: dd0b45538146cb6a54d6da7663b8c3afd16ebcfd
Version: dd0b45538146cb6a54d6da7663b8c3afd16ebcfd
Version: 22bc2a4814440c4a8979a381f46fec5d224f5c11
Version: 7cfe824f681e1aaac34ea64bb4def8a77801b672
Version: 4.19.189   
Version: 5.4.114   
Version: 5.10.32   
Version: 4.14.232   
Version: 5.11.16   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-35789",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-24T14:19:23.131138Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:33:29.281Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:21:47.402Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T11:51:59.910Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/mac80211/cfg.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ea9a0cfc07a7d3601cc680718d9cff0d6927a921",
              "status": "affected",
              "version": "a7f1721684628b8ae6015bca9a176046ee6f30cc",
              "versionType": "git"
            },
            {
              "lessThan": "be1dd9254fc115321d6fbee042026d42afc8d931",
              "status": "affected",
              "version": "bd7e90c82850f49c23004d54de14e46d373748a6",
              "versionType": "git"
            },
            {
              "lessThan": "e8b067c4058c0121ac8ca71559df8e2e08ff1a7e",
              "status": "affected",
              "version": "cc413b375c6d95e68a4629cb1ba9d099de78ebb9",
              "versionType": "git"
            },
            {
              "lessThan": "c8bddbd91bc8e42c961a5e2cec20ab879f21100f",
              "status": "affected",
              "version": "dd0b45538146cb6a54d6da7663b8c3afd16ebcfd",
              "versionType": "git"
            },
            {
              "lessThan": "7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b",
              "status": "affected",
              "version": "dd0b45538146cb6a54d6da7663b8c3afd16ebcfd",
              "versionType": "git"
            },
            {
              "lessThan": "6b948b54c8bd620725e0c906e44b10c0b13087a7",
              "status": "affected",
              "version": "dd0b45538146cb6a54d6da7663b8c3afd16ebcfd",
              "versionType": "git"
            },
            {
              "lessThan": "2884a50f52313a7a911de3afcad065ddbb3d78fc",
              "status": "affected",
              "version": "dd0b45538146cb6a54d6da7663b8c3afd16ebcfd",
              "versionType": "git"
            },
            {
              "lessThan": "e8678551c0243f799b4859448781cbec1bd6f1cb",
              "status": "affected",
              "version": "dd0b45538146cb6a54d6da7663b8c3afd16ebcfd",
              "versionType": "git"
            },
            {
              "lessThan": "4f2bdb3c5e3189297e156b3ff84b140423d64685",
              "status": "affected",
              "version": "dd0b45538146cb6a54d6da7663b8c3afd16ebcfd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "22bc2a4814440c4a8979a381f46fec5d224f5c11",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7cfe824f681e1aaac34ea64bb4def8a77801b672",
              "versionType": "git"
            },
            {
              "lessThan": "4.19.312",
              "status": "affected",
              "version": "4.19.189",
              "versionType": "semver"
            },
            {
              "lessThan": "5.4.274",
              "status": "affected",
              "version": "5.4.114",
              "versionType": "semver"
            },
            {
              "lessThan": "5.10.215",
              "status": "affected",
              "version": "5.10.32",
              "versionType": "semver"
            },
            {
              "lessThan": "4.15",
              "status": "affected",
              "version": "4.14.232",
              "versionType": "semver"
            },
            {
              "lessThan": "5.12",
              "status": "affected",
              "version": "5.11.16",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/mac80211/cfg.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.12"
            },
            {
              "lessThan": "5.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.312",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.274",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.215",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.154",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.84",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.24",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.312",
                  "versionStartIncluding": "4.19.189",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.274",
                  "versionStartIncluding": "5.4.114",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.215",
                  "versionStartIncluding": "5.10.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.154",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.84",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.24",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.12",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.3",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.14.232",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.11.16",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes\n\nWhen moving a station out of a VLAN and deleting the VLAN afterwards, the\nfast_rx entry still holds a pointer to the VLAN\u0027s netdev, which can cause\nuse-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx\nafter the VLAN change."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The stale `fast_rx-\u003edev` is dereferenced in the 802.11 receive fast path (`ieee80211_rx_8023`) when processing a data frame from the affected station, so the attacker must be an associated WiFi client within radio range of the AP. This is link-local 802.11 reachability, not routable network reach, hence Adjacent.\nAC:L - Once the station has been moved out of a VLAN that is subsequently deleted, every subsequent data frame the attacker transmits deterministically dereferences the freed netdev \u2014 there is no race to win and no memory layout the attacker cannot influence. In a hostapd dynamic-VLAN deployment the attacker induces the move itself by reauthenticating into a different RADIUS-assigned VLAN, and can repeat the sequence at will.\nPR:L - `ieee80211_check_fast_rx` only installs a `fast_rx` entry for a station with `WLAN_STA_AUTHORIZED` and a CCMP/GCMP PTK, so the attacker must be an authenticated, authorized client of the WLAN. That is an ordinary low-privileged network user, not an administrator.\nUI:N - No victim action is needed \u2014 the VLAN reassignment and teardown are performed automatically by hostapd in response to the attacker\u0027s own (re)authentication, and the attacker\u0027s own transmitted frames trigger the dereference.\nS:U - The use-after-free corrupts kernel memory and is exploited within the kernel\u0027s own security authority on the AP; there is no hypervisor, IOMMU, or sandbox boundary crossed.\nC:H - The freed `struct net_device` is read for `-\u003etstats`, `-\u003edev_addr` and `-\u003end_net`, and the skb is delivered into the stack using that stale pointer, so a groomed reclaim yields controlled kernel reads and misdirected traffic delivery; if the slot is reused by a live netdev, the station\u0027s frames leak into a different VLAN, defeating the segmentation the VLAN exists to enforce.\nI:H - `dev_sw_netstats_rx_add(fast_rx-\u003edev, skb-\u003elen)` reads a per-CPU pointer out of the freed object and writes `rx_bytes += skb-\u003elen` (attacker-chosen length) plus `rx_packets++` through it, giving a repeatable, attacker-influenced arbitrary-increment write primitive; combined with the UAF read this is exploitable for control-flow hijacking, and the stale `dev` also permits frame injection into the wrong VLAN.\nA:H - Dereferencing a freed `net_device` from RX softirq context \u2014 including an indirect write through a dangling `-\u003etstats` and passing the freed device to `eth_type_trans`/`netif_receive_skb` \u2014 reliably oopses or panics the access point kernel on the first frame after VLAN teardown."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:29:56.138Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921"
        },
        {
          "url": "https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931"
        },
        {
          "url": "https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e"
        },
        {
          "url": "https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f"
        },
        {
          "url": "https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b"
        },
        {
          "url": "https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7"
        },
        {
          "url": "https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc"
        },
        {
          "url": "https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb"
        },
        {
          "url": "https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685"
        }
      ],
      "title": "wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-35789",
    "datePublished": "2024-05-17T12:24:42.323Z",
    "dateReserved": "2024-05-17T12:19:12.338Z",
    "dateUpdated": "2026-08-05T11:29:56.138Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:21:47.402Z\"}}, {\"affected\": [{\"vendor\": \"Siemens\", \"product\": \"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"*\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"x_adpType\": \"supplier\", \"references\": [{\"url\": \"https://cert-portal.siemens.com/productcert/html/ssa-265688.html\"}], \"providerMetadata\": {\"orgId\": \"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e\", \"shortName\": \"siemens-SADP\", \"dateUpdated\": \"2026-05-12T11:51:59.910Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-35789\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-24T14:19:23.131138Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-24T14:19:27.474Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:A - The stale `fast_rx-\u003edev` is dereferenced in the 802.11 receive fast path (`ieee80211_rx_8023`) when processing a data frame from the affected station, so the attacker must be an associated WiFi client within radio range of the AP. This is link-local 802.11 reachability, not routable network reach, hence Adjacent.\\nAC:L - Once the station has been moved out of a VLAN that is subsequently deleted, every subsequent data frame the attacker transmits deterministically dereferences the freed netdev \\u2014 there is no race to win and no memory layout the attacker cannot influence. In a hostapd dynamic-VLAN deployment the attacker induces the move itself by reauthenticating into a different RADIUS-assigned VLAN, and can repeat the sequence at will.\\nPR:L - `ieee80211_check_fast_rx` only installs a `fast_rx` entry for a station with `WLAN_STA_AUTHORIZED` and a CCMP/GCMP PTK, so the attacker must be an authenticated, authorized client of the WLAN. That is an ordinary low-privileged network user, not an administrator.\\nUI:N - No victim action is needed \\u2014 the VLAN reassignment and teardown are performed automatically by hostapd in response to the attacker\u0027s own (re)authentication, and the attacker\u0027s own transmitted frames trigger the dereference.\\nS:U - The use-after-free corrupts kernel memory and is exploited within the kernel\u0027s own security authority on the AP; there is no hypervisor, IOMMU, or sandbox boundary crossed.\\nC:H - The freed `struct net_device` is read for `-\u003etstats`, `-\u003edev_addr` and `-\u003end_net`, and the skb is delivered into the stack using that stale pointer, so a groomed reclaim yields controlled kernel reads and misdirected traffic delivery; if the slot is reused by a live netdev, the station\u0027s frames leak into a different VLAN, defeating the segmentation the VLAN exists to enforce.\\nI:H - `dev_sw_netstats_rx_add(fast_rx-\u003edev, skb-\u003elen)` reads a per-CPU pointer out of the freed object and writes `rx_bytes += skb-\u003elen` (attacker-chosen length) plus `rx_packets++` through it, giving a repeatable, attacker-influenced arbitrary-increment write primitive; combined with the UAF read this is exploitable for control-flow hijacking, and the stale `dev` also permits frame injection into the wrong VLAN.\\nA:H - Dereferencing a freed `net_device` from RX softirq context \\u2014 including an indirect write through a dangling `-\u003etstats` and passing the freed device to `eth_type_trans`/`netif_receive_skb` \\u2014 reliably oopses or panics the access point kernel on the first frame after VLAN teardown.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"a7f1721684628b8ae6015bca9a176046ee6f30cc\", \"lessThan\": \"ea9a0cfc07a7d3601cc680718d9cff0d6927a921\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"bd7e90c82850f49c23004d54de14e46d373748a6\", \"lessThan\": \"be1dd9254fc115321d6fbee042026d42afc8d931\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"cc413b375c6d95e68a4629cb1ba9d099de78ebb9\", \"lessThan\": \"e8b067c4058c0121ac8ca71559df8e2e08ff1a7e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd0b45538146cb6a54d6da7663b8c3afd16ebcfd\", \"lessThan\": \"c8bddbd91bc8e42c961a5e2cec20ab879f21100f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd0b45538146cb6a54d6da7663b8c3afd16ebcfd\", \"lessThan\": \"7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd0b45538146cb6a54d6da7663b8c3afd16ebcfd\", \"lessThan\": \"6b948b54c8bd620725e0c906e44b10c0b13087a7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd0b45538146cb6a54d6da7663b8c3afd16ebcfd\", \"lessThan\": \"2884a50f52313a7a911de3afcad065ddbb3d78fc\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd0b45538146cb6a54d6da7663b8c3afd16ebcfd\", \"lessThan\": \"e8678551c0243f799b4859448781cbec1bd6f1cb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"dd0b45538146cb6a54d6da7663b8c3afd16ebcfd\", \"lessThan\": \"4f2bdb3c5e3189297e156b3ff84b140423d64685\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"22bc2a4814440c4a8979a381f46fec5d224f5c11\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7cfe824f681e1aaac34ea64bb4def8a77801b672\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"4.19.189\", \"lessThan\": \"4.19.312\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.4.114\", \"lessThan\": \"5.4.274\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.10.32\", \"lessThan\": \"5.10.215\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"4.14.232\", \"lessThan\": \"4.15\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.11.16\", \"lessThan\": \"5.12\", \"versionType\": \"semver\"}], \"programFiles\": [\"net/mac80211/cfg.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.12\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.12\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.312\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.274\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.215\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.154\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.84\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.24\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.12\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/mac80211/cfg.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921\"}, {\"url\": \"https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931\"}, {\"url\": \"https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e\"}, {\"url\": \"https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f\"}, {\"url\": \"https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b\"}, {\"url\": \"https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7\"}, {\"url\": \"https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc\"}, {\"url\": \"https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb\"}, {\"url\": \"https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nwifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes\\n\\nWhen moving a station out of a VLAN and deleting the VLAN afterwards, the\\nfast_rx entry still holds a pointer to the VLAN\u0027s netdev, which can cause\\nuse-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx\\nafter the VLAN change.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.312\", \"versionStartIncluding\": \"4.19.189\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.274\", \"versionStartIncluding\": \"5.4.114\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.215\", \"versionStartIncluding\": \"5.10.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.154\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.84\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.24\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.12\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.3\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"4.14.232\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.11.16\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:29:56.138Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-35789\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:29:56.138Z\", \"dateReserved\": \"2024-05-17T12:19:12.338Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-17T12:24:42.323Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…