Bug 2281213 (CVE-2024-35811)

Summary: CVE-2024-35811 kernel: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach
Product: [Other] Security Response Reporter: Zack Miele <zmiele>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: CLOSED DUPLICATE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: acaringi, allarkin, aquini, bhu, chwhite, cye, cyin, dbohanno, debarbos, dfreiber, drow, dvlasenk, esandeen, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lzampier, mleitner, mmilgram, mstowell, nmurray, ptalbert, rparrazo, rrobaina, rvrbovsk, rysulliv, scweaver, sidakwo, sukulkar, tglozar, tyberry, vkumar, wcosta, williams, wmealing, ycote, ykopkova, zhijwang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: kernel 4.19.312, kernel 5.4.274, kernel 5.10.215, kernel 5.15.154, kernel 6.1.84, kernel 6.6.24, kernel 6.7.12, kernel 6.8.3, kernel 6.9 Doc Type: If docs needed, set a value
Doc Text:
A use-after-free vulnerability was found in the `brcmf_cfg80211_detach` function of the `brcmfmac` driver in the Linux Kernel, which could lead to security risks or system instability. This issue was resolved to prevent unauthorized access to freed memory that could have been exploited for malicious purposes.
Story Points: ---
Clone Of: Environment:
Last Closed: 2024-05-28 09:47:18 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2281214    
Bug Blocks: 2281794    

Description Zack Miele 2024-05-17 23:40:36 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach

The Linux kernel CVE team has assigned CVE-2024-35811 to this issue.

Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051741-CVE-2024-35811-9306@gregkh/T

Comment 1 Zack Miele 2024-05-17 23:41:14 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2281214]