CVE-2024-38562

high
Published 2024-09-24 · Modified 2024-11-03
CVSS v3
CVSS v2
VIR risk
8.0

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: Avoid address calculations via out of bounds array indexing Before request->channels[] can be used, request->n_channels must be set. Additionally, address calculations for memory after the "channels" array need to be calculated from the allocation base ("request") rather than via the first "out of bounds" index of "channels", otherwise run-time bounds checking will throw a warning.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-6997.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2301543

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2300448

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2297568

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2293685

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2293431

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2293423

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2293420

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2293364

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2293348

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2284549

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2283894

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2281677

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2278318

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2278252

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2278250

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2278248

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2278245

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2278167

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2273270

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2265271

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-38562

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-38562.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:6997

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
suse slesaffected
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed6.8.12-1
debian debiansidfixed6.8.12-1
debian debiantrixiefixed6.8.12-1

References

Verify integrity in audit chain (admin only). AS-IS.