CVE-2024-47724 (GCVE-0-2024-47724)
Vulnerability from cvelistv5
Published
2024-10-21 12:13
Modified
2026-08-05 11:39
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: use work queue to process beacon tx event Commit 3a415daa3e8b ("wifi: ath11k: add P2P IE in beacon template") from Feb 28, 2024 (linux-next), leads to the following Smatch static checker warning: drivers/net/wireless/ath/ath11k/wmi.c:1742 ath11k_wmi_p2p_go_bcn_ie() warn: sleeping in atomic context The reason is that ath11k_bcn_tx_status_event() will directly call might sleep function ath11k_wmi_cmd_send() during RCU read-side critical sections. The call trace is like: ath11k_bcn_tx_status_event() -> rcu_read_lock() -> ath11k_mac_bcn_tx_event() -> ath11k_mac_setup_bcn_tmpl() …… -> ath11k_wmi_bcn_tmpl() -> ath11k_wmi_cmd_send() -> rcu_read_unlock() Commit 886433a98425 ("ath11k: add support for BSS color change") added the ath11k_mac_bcn_tx_event(), commit 01e782c89108 ("ath11k: fix warning of RCU usage for ath11k_mac_get_arvif_by_vdev_id()") added the RCU lock to avoid warning but also introduced this BUG. Use work queue to avoid directly calling ath11k_mac_bcn_tx_event() during RCU critical sections. No need to worry about the deletion of vif because cancel_work_sync() will drop the work if it doesn't start or block vif deletion until the running work is done. Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30
Impacted products
Vendor Product Version
Linux Linux Version: 3a415daa3e8ba65f1cc976c172a5ab69bdc17e69
Version: 3a415daa3e8ba65f1cc976c172a5ab69bdc17e69
Version: 3a415daa3e8ba65f1cc976c172a5ab69bdc17e69
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-47724",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-21T13:01:30.955907Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-21T13:04:16.907Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/core.h",
            "drivers/net/wireless/ath/ath11k/mac.c",
            "drivers/net/wireless/ath/ath11k/wmi.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "dbd51da69dda1137723b8f66460bf99a9dac8dd2",
              "status": "affected",
              "version": "3a415daa3e8ba65f1cc976c172a5ab69bdc17e69",
              "versionType": "git"
            },
            {
              "lessThan": "6db232905e094e64abff1f18249905d068285e09",
              "status": "affected",
              "version": "3a415daa3e8ba65f1cc976c172a5ab69bdc17e69",
              "versionType": "git"
            },
            {
              "lessThan": "177b49dbf9c1d8f9f25a22ffafa416fc2c8aa6a3",
              "status": "affected",
              "version": "3a415daa3e8ba65f1cc976c172a5ab69bdc17e69",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/core.h",
            "drivers/net/wireless/ath/ath11k/mac.c",
            "drivers/net/wireless/ath/ath11k/wmi.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "lessThan": "6.10",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.13",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.2",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: use work queue to process beacon tx event\n\nCommit 3a415daa3e8b (\"wifi: ath11k: add P2P IE in beacon template\")\nfrom Feb 28, 2024 (linux-next), leads to the following Smatch static\nchecker warning:\n\ndrivers/net/wireless/ath/ath11k/wmi.c:1742 ath11k_wmi_p2p_go_bcn_ie()\nwarn: sleeping in atomic context\n\nThe reason is that ath11k_bcn_tx_status_event() will directly call might\nsleep function ath11k_wmi_cmd_send() during RCU read-side critical\nsections. The call trace is like:\n\nath11k_bcn_tx_status_event()\n-\u003e rcu_read_lock()\n-\u003e ath11k_mac_bcn_tx_event()\n\t-\u003e ath11k_mac_setup_bcn_tmpl()\n\t\u2026\u2026\n\t\t-\u003e ath11k_wmi_bcn_tmpl()\n\t\t\t-\u003e ath11k_wmi_cmd_send()\n-\u003e rcu_read_unlock()\n\nCommit 886433a98425 (\"ath11k: add support for BSS color change\") added the\nath11k_mac_bcn_tx_event(), commit 01e782c89108 (\"ath11k: fix warning\nof RCU usage for ath11k_mac_get_arvif_by_vdev_id()\") added the RCU lock\nto avoid warning but also introduced this BUG.\n\nUse work queue to avoid directly calling ath11k_mac_bcn_tx_event()\nduring RCU critical sections. No need to worry about the deletion of vif\nbecause cancel_work_sync() will drop the work if it doesn\u0027t start or\nblock vif deletion until the running work is done.\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The trigger is the ath11k AP\u0027s BSS color-change state, which an attacker forces by transmitting beacons carrying the AP\u0027s BSS color in the HE Operation IE, causing firmware OBSS color-collision detection and an automatic hostapd color change. This requires only being within WiFi radio range of the target AP, not a routable network path.\nAC:L - Once a color change is active, every beacon TX status event (roughly every 100 ms) deterministically enters ath11k_mac_bcn_tx_event() and calls the might_sleep() WMI send from tasklet/RCU context, and the attacker controls the collision beacon that starts the color change. No unpredictable memory layout or victim state is needed.\nPR:N - Injecting a beacon frame with a colliding BSS color requires no association, authentication, or credentials on the target AP, and no account on the host. The color change that arms the bug is initiated automatically by hostapd in response to the attacker\u0027s frame.\nUI:N - No action by any user or administrator is needed; the OBSS color-collision notification and the resulting color change are handled automatically by the firmware, mac80211, and hostapd.\nS:U - The corruption and crash are confined to the kernel of the AP device itself, with no crossing into a different security authority such as a hypervisor or IOMMU boundary.\nC:H - Sleeping inside the RCU read-side critical section makes the voluntary schedule a quiescent state, so synchronize_rcu() in the pdev/vdev teardown path can complete while ath11k_mac_setup_bcn_tmpl() still dereferences the freed ath11k_vif/ath11k structures, yielding a use-after-free read of kernel heap contents.\nI:H - The same use-after-free window lets the driver write into freed memory (arvif-\u003ersnie_present, wpaie_present, bcca_zero_sent, and WMI command buffers built from freed ar/wmi pointers), and the missing conf_mutex means these writes race with vdev deletion; additionally wait_event_timeout() in tasklet context corrupts an unrelated task\u0027s state and leaves a wait-queue entry on the interrupt stack.\nA:H - Calling a might_sleep() function from the CE tasklet produces \"BUG: sleeping function called from invalid context\" and, when WMI credits are unavailable, \"BUG: scheduling while atomic\" with a potential panic; the tasklet never reaches its enable_irq(), permanently disabling the Copy Engine interrupt and wedging the wireless device."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:39:44.134Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dbd51da69dda1137723b8f66460bf99a9dac8dd2"
        },
        {
          "url": "https://git.kernel.org/stable/c/6db232905e094e64abff1f18249905d068285e09"
        },
        {
          "url": "https://git.kernel.org/stable/c/177b49dbf9c1d8f9f25a22ffafa416fc2c8aa6a3"
        }
      ],
      "title": "wifi: ath11k: use work queue to process beacon tx event",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-47724",
    "datePublished": "2024-10-21T12:13:58.267Z",
    "dateReserved": "2024-09-30T16:00:12.956Z",
    "dateUpdated": "2026-08-05T11:39:44.134Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-47724\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-21T13:01:30.955907Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-21T13:01:34.056Z\"}}], \"cna\": {\"title\": \"wifi: ath11k: use work queue to process beacon tx event\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"3a415daa3e8ba65f1cc976c172a5ab69bdc17e69\", \"lessThan\": \"dbd51da69dda1137723b8f66460bf99a9dac8dd2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"3a415daa3e8ba65f1cc976c172a5ab69bdc17e69\", \"lessThan\": \"6db232905e094e64abff1f18249905d068285e09\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"3a415daa3e8ba65f1cc976c172a5ab69bdc17e69\", \"lessThan\": \"177b49dbf9c1d8f9f25a22ffafa416fc2c8aa6a3\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/wireless/ath/ath11k/core.h\", \"drivers/net/wireless/ath/ath11k/mac.c\", \"drivers/net/wireless/ath/ath11k/wmi.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.10\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.10\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.10.13\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/wireless/ath/ath11k/core.h\", \"drivers/net/wireless/ath/ath11k/mac.c\", \"drivers/net/wireless/ath/ath11k/wmi.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/dbd51da69dda1137723b8f66460bf99a9dac8dd2\"}, {\"url\": \"https://git.kernel.org/stable/c/6db232905e094e64abff1f18249905d068285e09\"}, {\"url\": \"https://git.kernel.org/stable/c/177b49dbf9c1d8f9f25a22ffafa416fc2c8aa6a3\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nwifi: ath11k: use work queue to process beacon tx event\\n\\nCommit 3a415daa3e8b (\\\"wifi: ath11k: add P2P IE in beacon template\\\")\\nfrom Feb 28, 2024 (linux-next), leads to the following Smatch static\\nchecker warning:\\n\\ndrivers/net/wireless/ath/ath11k/wmi.c:1742 ath11k_wmi_p2p_go_bcn_ie()\\nwarn: sleeping in atomic context\\n\\nThe reason is that ath11k_bcn_tx_status_event() will directly call might\\nsleep function ath11k_wmi_cmd_send() during RCU read-side critical\\nsections. The call trace is like:\\n\\nath11k_bcn_tx_status_event()\\n-\u003e rcu_read_lock()\\n-\u003e ath11k_mac_bcn_tx_event()\\n\\t-\u003e ath11k_mac_setup_bcn_tmpl()\\n\\t\\u2026\\u2026\\n\\t\\t-\u003e ath11k_wmi_bcn_tmpl()\\n\\t\\t\\t-\u003e ath11k_wmi_cmd_send()\\n-\u003e rcu_read_unlock()\\n\\nCommit 886433a98425 (\\\"ath11k: add support for BSS color change\\\") added the\\nath11k_mac_bcn_tx_event(), commit 01e782c89108 (\\\"ath11k: fix warning\\nof RCU usage for ath11k_mac_get_arvif_by_vdev_id()\\\") added the RCU lock\\nto avoid warning but also introduced this BUG.\\n\\nUse work queue to avoid directly calling ath11k_mac_bcn_tx_event()\\nduring RCU critical sections. No need to worry about the deletion of vif\\nbecause cancel_work_sync() will drop the work if it doesn\u0027t start or\\nblock vif deletion until the running work is done.\\n\\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.13\", \"versionStartIncluding\": \"6.10\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.2\", \"versionStartIncluding\": \"6.10\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"6.10\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-11T20:39:32.401Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-47724\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-05-11T20:39:32.401Z\", \"dateReserved\": \"2024-09-30T16:00:12.956Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T12:13:58.267Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…