CVE-2024-27434

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP flag for the GTK, it can even make the firmware crash. in case the AP is configured with: group cipher TKIP and MFPC. We would send the GTK with cipher = TKIP and MFP which is of course not possible.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

26 Sep 2025, 16:21

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715 - () https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715 - Patch
References () https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628 - () https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628 - Patch
References () https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8 - () https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8 - Patch
References () https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c - () https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

21 Nov 2024, 09:04

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715 - () https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715 -
References () https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628 - () https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628 -
References () https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8 - () https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8 -
References () https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c - () https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: wifi: iwlwifi: mvm: no configure el indicador MFP para GTK El firmware no necesita el indicador MFP para GTK, incluso puede provocar que el firmware falle. en caso de que el AP esté configurado con: cifrado de grupo TKIP y MFPC. Enviaríamos el GTK con cifrado = TKIP y MFP, lo cual, por supuesto, no es posible.

17 May 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 13:15

Updated : 2025-09-26 16:21


NVD link : CVE-2024-27434

Mitre link : CVE-2024-27434

CVE.ORG link : CVE-2024-27434


JSON object : View

Products Affected

linux

  • linux_kernel