Overview: CVE-2024-40979 is a vulnerability in the Linux kernel's ath12k Wi-Fi driver that can lead to a kernel crash during system resume. This occurs due to improper handling of QMI target memory, specifically when DMA remapping is not supported, causing incorrect memory deallocation. It affects Linux kernel versions utilizing the ath12k driver. Severity: Rated as Medium (CVSS 5.5), this vulnerability has a local attack vector with low attack complexity, requiring local privileges. The potential impact is a denial of service (system crash), with no impact on confidentiality or integrity. Exploitation Status: There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3, < 6.9.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.