Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix array out-of-bound access in SoC stats Currently, the ath12k_soc_dp_stats::hal_reo_error array is defined with a maximum size of DP_REO_DST_RING_MAX. However, the ath12k_dp_rx_process() function access ath12k_soc_dp_stats::hal_reo_error using the REO destination SRNG ring ID, which is incorrect. SRNG ring ID differ from normal ring ID, and this usage leads to out-of-bounds array access. To fix this issue, modify ath12k_dp_rx_process() to use the normal ring ID directly instead of the SRNG ring ID to avoid out-of-bounds array access. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 6.6.55 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/a4aef827a41cdaf6201bbaf773c1eae4e20e967bPatch
- https://git.kernel.org/stable/c/ad791e3ec60cb66c1e4dc121ffbf872df312427dPatch
- https://git.kernel.org/stable/c/d0e4274d9dc9f8409d56d622cd3ecf7b6fd49e2fPatch
- https://git.kernel.org/stable/c/e106b7ad13c1d246adaa57df73edb8f8b8acb240Patch
FAQ
What is CVE-2024-49931?
CVE-2024-49931 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix array out-of-bound access in SoC stats Currently, the ath12k_soc_dp_stats::hal_reo_error array is defined with a...
How severe is CVE-2024-49931?
CVE-2024-49931 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-49931?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.