CVE-2024-36941: wifi: nl80211: don't free NULL coalescing rule
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: don't free NULL coalescing rule
If the parsing fails, we can dereference a NULL pointer here.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: don't free NULL coalescing rule
The Linux kernel CVE team has assigned CVE-2024-36941 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024053043-CVE-2024-36941-b3a3@gregkh/T
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36941?
CVE-2024-36941 is classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-36941?
To mitigate CVE-2024-36941, update your Linux kernel to any of the following versions: 4.19.314, 5.4.276, 5.10.217, 5.15.159, 6.1.91, 6.6.31, 6.8.10, or 6.9.
Which Linux kernel versions are affected by CVE-2024-36941?
CVE-2024-36941 affects Linux kernel versions prior to 4.19.314, 5.4.276, 5.10.217, 5.15.159, 6.1.91, 6.6.31, 6.8.10, and 6.9.
What causes CVE-2024-36941?
CVE-2024-36941 is caused by a NULL pointer dereference in the nl80211 subsystem of the Linux kernel when parsing fails.
Is CVE-2024-36941 exploitable in all system configurations?
The exploitability of CVE-2024-36941 may vary depending on the specific system configurations and the presence of other security controls.