{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-26637","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-19T14:20:24.137Z","datePublished":"2024-03-18T10:14:48.378Z","dateUpdated":"2026-08-05T11:26:26.884Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:26:26.884Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: rely on mac80211 debugfs handling for vif\n\nmac80211 started to delete debugfs entries in certain cases, causing a\nath11k to crash when it tried to delete the entries later. Fix this by\nrelying on mac80211 to delete the entries when appropriate and adding\nthem from the vif_add_debugfs handler."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The stale-dentry free is reached only through local control-plane operations on the wireless netdev — rtnetlink/nl80211 interface down or delete, MAC/iftype change, or a local system-suspend request — not from any received 802.11 frame or network packet. No remote or adjacent peer can drive `drv_remove_interface()`.\nAC:L - The failure is deterministic, not a race: once mac80211's `ieee80211_debugfs_recreate_netdev()` has dput the \"twt\" dentry, ath11k's very next `debugfs_remove_recursive(arvif->debugfs_twt)` in the same `drv_remove_interface()` call always operates on freed memory. The attacker needs no specific timing and can pre-shape the dentry slab at leisure before triggering.\nPR:L - `__ieee80211_suspend()` (net/mac80211/pm.c:164) tears every running vif out of the driver whenever WoWLAN is not armed, and suspend is routinely available to an ordinary logged-in local user via systemd-logind/polkit or lid close on ath11k-equipped laptops; the equivalent hotspot-toggle teardown is user-accessible on Android. No CAP_NET_ADMIN is strictly required for that route, so the unprivileged-local case is the correct, higher-severity reading.\nUI:N - The attacker performs the triggering action (suspend request or interface teardown) directly; no separate victim needs to be induced into doing anything.\nS:U - The corruption is confined to kernel memory within the same security authority — a driver debugfs dentry and whatever kernel slab object reclaims it. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free on a freed dentry that debugfs then walks (`d_inode`, `d_subdirs`, `d_fsdata`); if the slab object is reclaimed by a sprayed dentry, `remove_one()`/`__debugfs_file_removed()` dereference attacker-influenced pointers, yielding an arbitrary-read primitive rather than a bounded leak.\nI:H - `simple_recursive_removal()` opens with `dget()`, a lockref write into freed memory, and then `d_invalidate()`/`dput()`s an entire subtree reachable from the reclaimed object — corrupting refcounts on live filesystem dentries and inodes, which is a standard route to a controlled write and control-flow hijack.\nA:H - Every affected interface teardown reliably oopses the kernel (dereferencing a freed dentry's `d_inode` under `inode_lock()`), and the underflowing `simple_release_fs()` mount count compounds it; a use-after-free of this kind crashes the machine even when not further exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath11k/core.h","drivers/net/wireless/ath/ath11k/debugfs.c","drivers/net/wireless/ath/ath11k/debugfs.h","drivers/net/wireless/ath/ath11k/mac.c"],"versions":[{"version":"0a3d898ee9a8303d5b3982b97ef0703919c3ea76","lessThan":"aa74ce30a8a40d19a4256de4ae5322e71344a274","status":"affected","versionType":"git"},{"version":"0a3d898ee9a8303d5b3982b97ef0703919c3ea76","lessThan":"556857aa1d0855aba02b1c63bc52b91ec63fc2cc","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath11k/core.h","drivers/net/wireless/ath/ath11k/debugfs.c","drivers/net/wireless/ath/ath11k/debugfs.h","drivers/net/wireless/ath/ath11k/mac.c"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"6.7.3","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.7.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/aa74ce30a8a40d19a4256de4ae5322e71344a274"},{"url":"https://git.kernel.org/stable/c/556857aa1d0855aba02b1c63bc52b91ec63fc2cc"}],"title":"wifi: ath11k: rely on mac80211 debugfs handling for vif","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:07:19.812Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/aa74ce30a8a40d19a4256de4ae5322e71344a274","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/556857aa1d0855aba02b1c63bc52b91ec63fc2cc","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-26637","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T15:55:06.774541Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:33:16.633Z"}}]}}