CVE-2024-35811
Published: May 17, 2024
Modified: May 12, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach This is the candidate patch of CVE-2023-47233 : https://nvd.nist.gov/vuln/detail/CVE-2023-47233 In brcm80211 driver,it starts with the following invoking chain to start init a timeout worker: ->brcmf_usb_probe ->brcmf_usb_probe_cb ->brcmf_attach ->brcmf_bus_started ->brcmf_cfg80211_attach ->wl_init_priv ->brcmf_init_escan ->INIT_WORK(&cfg->escan_timeout_work, brcmf_cfg80211_escan_timeout_worker); If we disconnect the USB by hotplug, it will call brcmf_usb_disconnect to make cleanup. The invoking chain is : brcmf_usb_disconnect ->brcmf_usb_disconnect_cb ->brcmf_detach ->brcmf_cfg80211_detach ->kfree(cfg); While the timeout woker may still be running. This will cause a use-after-free bug on cfg in brcmf_cfg80211_escan_timeout_worker. Fix it by deleting the timer and canceling the worker in brcmf_cfg80211_detach. [[email protected]: keep timer delete as is and cancel work just before free]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected e756af5b30b008f6ffcfebf8ad0b477f6f225b62 - < 202c503935042272e2f9e1bb549d5f69a8681169affected e756af5b30b008f6ffcfebf8ad0b477f6f225b62 - < 8e3f03f4ef7c36091f46e7349096efb5a2cdb3a1affected e756af5b30b008f6ffcfebf8ad0b477f6f225b62 - < bacb8c3ab86dcd760c15903fcee58169bc3026aaaffected e756af5b30b008f6ffcfebf8ad0b477f6f225b62 - < 8c36205123dc57349b59b4f1a2301eb278cbc731affected e756af5b30b008f6ffcfebf8ad0b477f6f225b62 - < 0b812f706fd7090be74812101114a0e165b36744+4 more versions |
Linux | Linux | affected 3.7unaffected 0 - < 3.7unaffected 4.19.312 - <= 4.19.*unaffected 5.4.274 - <= 5.4.*unaffected 5.10.215 - <= 5.10.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now