CVE-2024-43847·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid memory access while processing fragmented packets The monitor ring and the reo reinject ring share the same ring mask index. When the driver receives an interrupt for the reo reinject ring, the monitor ring is also processed, leading to invalid memory access. Since monitor support is not yet enabled in ath12k, the ring mask for the monitor ring should be removed. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.3
- Published
- 2024-08-17
Affected versions
From: 6.7
Until: 6.10.3
Fixed in: 6.10.3
How to fix this CVE
Update your Linux kernel to version 6.10.3 or later to resolve a critical memory access flaw in the ath12k Wi-Fi driver that occurs when processing fragmented packets. The vulnerability stems from improper ring mask handling between the monitor ring and reo reinject ring, causing kernel memory corruption during interrupt processing. Apply the patch immediately if you are running kernel versions 6.7 through 6.10.2 with ath12k wireless hardware.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your current kernel version: uname -r — ensure it is 6.10.3 or later
- Verify if ath12k module is loaded: lsmod | grep ath12k — if present, the vulnerable code path is available
- Check dmesg for memory access violations: sudo dmesg | grep -i 'segfault\|fault\|oops' — look for timestamps correlating with wireless driver initialization
- Confirm the fix: grep -r 'ring mask for the monitor ring' /boot/config-$(uname -r) or check kernel commit 073f9f249eecd64ab9d59c91c4a23cfdcc02afe4 is applied via git log
FAQ
What is CVE-2024-43847?
CVE-2024-43847 is a memory corruption vulnerability in the Linux kernel's ath12k Wi-Fi driver where shared ring mask indices between the monitor ring and reo reinject ring cause invalid memory access during packet fragmentation processing.
Is CVE-2024-43847 being actively exploited?
No, there is no evidence of active exploitation in the wild, and no public exploit code is available. However, the high CVSS score (8.8) indicates significant potential impact if leveraged.
What versions of Kernel are affected by CVE-2024-43847?
Linux kernel versions 6.7 through 6.10.2 are affected. Version 6.10.3 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-43847?
Run uname -r to check your kernel version. If it shows 6.7.x through 6.10.2 AND lsmod | grep ath12k shows the module is loaded, your system is vulnerable.
Does Defensia detect CVE-2024-43847?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-43847 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-43847. Free for 1 server.
Get started free