Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-27434

18
FAUCET Score

CVE-2024-27434 is a medium-severity vulnerability in the Linux kernel's iwlwifi driver, specifically affecting the mvm component. It involves an incorrect setting of the MFP flag for the Group Temporal Key (GTK) when the Access Point (AP) is configured with TKIP group cipher and MFPC, which can lead to firmware crashes. The vulnerability has a CVSS score of 5.5, indicating a local attack vector with low complexity, requiring low privileges, and resulting in high availability impact (denial of service). There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.2, < 6.6.23CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.7.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.8, < 6.8.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
13.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 57th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: 16989-17084Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: 17785-17084Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: azl3 hyperv-daemons 6.6.22.1-2 on Azure Linux 3.0Fixed in: 6.6.35.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.16.1.rt7.357.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.16.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.31.1.el9_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (3)

microsoft2024-Sep/CVE-2024-27434

CVE-2024-27434

Sep 10, 2024
redhatCVE-2024-27434Moderate

kernel: wifi: iwlwifi: mvm: don&#39;t set the MFP flag for the GTK

May 17, 2024
microsoft2024-May/CVE-2024-27434Moderate

wifi: iwlwifi: mvm: don't set the MFP flag for the GTK

May 14, 2024

References

git.kernel.org / stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715
Patch
git.kernel.org / stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628
Patch
git.kernel.org / stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8
Patch
git.kernel.org / stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c
Patch