CVE-2024-49929: wifi: iwlwifi: mvm: avoid NULL pointer dereference

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: avoid NULL pointer dereference

iwl_mvm_tx_skb_sta() and iwl_mvm_tx_mpdu() verify that the mvmvsta
pointer is not NULL.
It retrieves this pointer using iwl_mvm_sta_from_mac80211, which is
dereferencing the ieee80211_sta pointer.
If sta is NULL, iwl_mvm_sta_from_mac80211 will dereference a NULL
pointer.
Fix this by checking the sta pointer before retrieving the mvmsta
from it. If sta is not NULL, then mvmsta isn't either.

Classification

CVE ID: CVE-2024-49929

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.08% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/cbc6fc9cfcde151ff5eadaefdc6155f99579384f
https://git.kernel.org/stable/c/6dcadb2ed3b76623ab96e3e7fbeda1a374d01c28
https://git.kernel.org/stable/c/cdbf51bfa4b0411820806777da36d93d49bc49a1
https://git.kernel.org/stable/c/c0b4f5d94934c290479180868a32c15ba36a6d9e
https://git.kernel.org/stable/c/557a6cd847645e667f3b362560bd7e7c09aac284

Timeline