Executive Summary

Informations
Name CVE-2024-43841 First vendor Publication 2024-08-17
Vendor Cve Last vendor Modification 2024-10-29

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Overall CVSS Score 3.3
Base Score 3.3 Environmental Score 3.3
impact SubScore 1.4 Temporal Score 3.3
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact Low Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

wifi: virt_wifi: avoid reporting connection success with wrong SSID

When user issues a connection with a different SSID than the one virt_wifi has advertised, the __cfg80211_connect_result() will trigger the warning: WARN_ON(bss_not_found).

The issue is because the connection code in virt_wifi does not check the SSID from user space (it only checks the BSSID), and virt_wifi will call cfg80211_connect_result() with WLAN_STATUS_SUCCESS even if the SSID is different from the one virt_wifi has advertised. Eventually cfg80211 won't be able to find the cfg80211_bss and generate the warning.

Fixed it by checking the SSID (from user space) in the connection code.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43841

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3645

Sources (Detail)

https://git.kernel.org/stable/c/05c4488a0e446c6ccde9f22b573950665e1cd414
https://git.kernel.org/stable/c/36e92b5edc8e0daa18e9325674313802ce3fbc29
https://git.kernel.org/stable/c/416d3c1538df005195721a200b0371d39636e05d
https://git.kernel.org/stable/c/93e898a264b4e0a475552ba9f99a016eb43ef942
https://git.kernel.org/stable/c/994fc2164a03200c3bf42fb45b3d49d9d6d33a4d
https://git.kernel.org/stable/c/b5d14b0c6716fad7f0c94ac6e1d6f60a49f985c7
https://git.kernel.org/stable/c/d3cc85a10abc8eae48988336cdd3689ab92581b3
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
Date Informations
2025-01-08 03:04:33
  • Multiple Updates
2025-01-07 03:04:06
  • Multiple Updates
2024-12-25 03:02:44
  • Multiple Updates
2024-12-12 03:05:40
  • Multiple Updates
2024-11-23 03:02:42
  • Multiple Updates
2024-11-22 03:00:53
  • Multiple Updates
2024-11-20 02:59:13
  • Multiple Updates
2024-11-14 02:59:32
  • Multiple Updates
2024-11-09 02:59:32
  • Multiple Updates
2024-10-29 21:28:14
  • Multiple Updates
2024-08-19 13:27:29
  • Multiple Updates
2024-08-17 17:27:28
  • First insertion