Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.5, < 5.10.214 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/71d4186d470e9cda7cd1a0921b4afda737c6f641Patch
- https://git.kernel.org/stable/c/783d413f332a3ebec916664b366c28f58147f82cPatch
- https://git.kernel.org/stable/c/96aa40761673da045a7774f874487cdb50c6a2f7Patch
- https://git.kernel.org/stable/c/c855a1a5b7e3de57e6b1b29563113d5e3bfdb89aPatch
- https://git.kernel.org/stable/c/ea1d166fae14e05d49ffb0ea9fcd4658f8d3dceaPatch
- https://git.kernel.org/stable/c/fabe2db7de32a881e437ee69db32e0de785a6209Patch
- https://git.kernel.org/stable/c/fec14d1cdd92f340b9ba2bd220abf96f9609f2a9Patch
- https://git.kernel.org/stable/c/71d4186d470e9cda7cd1a0921b4afda737c6f641Patch
- https://git.kernel.org/stable/c/783d413f332a3ebec916664b366c28f58147f82cPatch
- https://git.kernel.org/stable/c/96aa40761673da045a7774f874487cdb50c6a2f7Patch
- https://git.kernel.org/stable/c/c855a1a5b7e3de57e6b1b29563113d5e3bfdb89aPatch
- https://git.kernel.org/stable/c/ea1d166fae14e05d49ffb0ea9fcd4658f8d3dceaPatch
- https://git.kernel.org/stable/c/fabe2db7de32a881e437ee69db32e0de785a6209Patch
- https://git.kernel.org/stable/c/fec14d1cdd92f340b9ba2bd220abf96f9609f2a9Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2024-35845?
CVE-2024-35845 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is ...
How severe is CVE-2024-35845?
CVE-2024-35845 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-35845?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.