CVE-2024-40929 is a high-severity out-of-bounds read vulnerability (CWE-125) affecting the Linux kernel's iwlwifi driver. Specifically, it occurs when the n_ssids value is zero but the ssids pointer is still valid, leading to an invalid memory access. This vulnerability has a CVSS score of 7.1, indicating a high potential impact on confidentiality and availability. The attack vector is local with low attack complexity and requires low privileges. Successful exploitation could lead to information disclosure or denial of service. Currently, there is no evidence of active exploitation, nor is there any public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a newly disclosed vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.17, < 5.10.221CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.162CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.95CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.35CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.9.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.