Vulnerability identifier: #VU99032
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-667
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ieee80211_do_stop() function in net/mac80211/iface.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/f232916fab67ca1c3425926df4a866e59ff26908
https://git.kernel.org/stable/c/acb53a716e492a02479345157c43f21edc8bc64b
https://git.kernel.org/stable/c/db5ca4b42ccfa42d2af7b335ff12578e57775c02
https://git.kernel.org/stable/c/058c9026ad79dc98572442fd4c7e9a36aba6f596
https://git.kernel.org/stable/c/eab272972cffff9cd973b8e4055a8e81c64f7e6a
https://git.kernel.org/stable/c/ad4b7068b101fbbb4a9ca4b99b25eb051a9482ec
https://git.kernel.org/stable/c/9d301de12da6e1bb069a9835c38359b8e8135121
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.