HomeDefectsLIN1024-1573
Fixed

LIN1024-1573 : Security Advisory - linux - CVE-2023-52777

Created: May 21, 2024    Updated: Aug 28, 2024
Resolved Date: May 22, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix gtk offload status event locking

The ath11k active pdevs are protected by RCU but the gtk offload status
event handling code calling ath11k_mac_get_arvif_by_vdev_id() was not
marked as a read-side critical section.

Mark the code in question as an RCU read-side critical section to avoid
any potential use-after-free issues.

Compile tested only.

CREATE(Triage):(User=admin) CVE-2023-52777 (https://nvd.nist.gov/vuln/detail/CVE-2023-52777)

CVEs