CVE-2024-35845: wifi: iwlwifi: dbg-tlv: ensure NUL termination
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: dbg-tlv: ensure NUL termination
The iwlfwinidebuginfotlv is used as a string, so we must ensure the string is terminated correctly before using it.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: dbg-tlv: ensure NUL termination
The Linux kernel CVE team has assigned CVE-2024-35845 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051718-CVE-2024-35845-65bd@gregkh/T
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35845?
The severity of CVE-2024-35845 is classified as medium due to potential string handling issues in the Linux kernel.
How do I fix CVE-2024-35845?
To fix CVE-2024-35845, you should update to the recommended kernel versions specified in the vulnerability details.
Which versions of the Linux kernel are affected by CVE-2024-35845?
CVE-2024-35845 affects several versions of the Linux kernel prior to 5.10.214, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, and 6.9.
What type of vulnerability is CVE-2024-35845?
CVE-2024-35845 is a string termination vulnerability in the Linux kernel related to the iwlwifi driver.
Is CVE-2024-35845 specific to any Linux distributions?
Yes, CVE-2024-35845 particularly affects Red Hat and Debian-based distributions using specific kernel versions.