U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-53189

Change History

New CVE Received from kernel.org 12/27/2024 9:15:26 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

wifi: nl80211: fix bounds checker error in nl80211_parse_sched_scan

The channels array in the cfg80211_scan_request has a __counted_by
attribute attached to it, which points to the n_channels variable. This
attribute is used in bounds checking, and if it is not set before the
array is filled, then the bounds sanitizer will issue a warning or a
kernel panic if CONFIG_UBSAN_TRAP is set.

This patch sets the size of allocated memory as the initial value for
n_channels. It is updated with the actual number of added elements after
the array is filled.
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/1a7b62ddf2c7642878c24f0e556041bb58c37527
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/9c46a3a5b394d6d123866aa44436fc2cd342eb0d
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/d4ef643ea78c59c22546046c25dc6e7206267672