CVE-2024-35845

Source
https://cve.org/CVERecord?id=CVE-2024-35845
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35845.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35845
Downstream
Related
Published
2024-05-17T14:40:12.134Z
Modified
2026-05-28T03:53:33.336080509Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
wifi: iwlwifi: dbg-tlv: ensure NUL termination
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: dbg-tlv: ensure NUL termination

The iwlfwinidebuginfo_tlv is used as a string, so we must ensure the string is terminated correctly before using it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35845.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a9248de42464e546b624e3fc6a8b04b991af3591
Fixed
fabe2db7de32a881e437ee69db32e0de785a6209
Fixed
96aa40761673da045a7774f874487cdb50c6a2f7
Fixed
c855a1a5b7e3de57e6b1b29563113d5e3bfdb89a
Fixed
783d413f332a3ebec916664b366c28f58147f82c
Fixed
fec14d1cdd92f340b9ba2bd220abf96f9609f2a9
Fixed
71d4186d470e9cda7cd1a0921b4afda737c6f641
Fixed
ea1d166fae14e05d49ffb0ea9fcd4658f8d3dcea

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35845.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.214
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.153
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.83
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.23
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.11
Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.8.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35845.json"