CVE-2023-7042: Kernel: null pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
A null pointer dereference vulnerability in ath10kwmitlvoppullmgmttxcomplev() in drivers/net/wireless/ath/ath10k/wmi-tlv.c in the Linux kernel, which could be exploited to trigger denial of service.
Refer: https://patchwork.kernel.org/project/linux-wireless/patch/20231208043433.271449-1-hdthky0@gmail.com/
Other sources
A null pointer dereference vulnerability was found in ath10kwmitlvoppullmgmttxcomplev() in drivers/net/wireless/ath/ath10k/wmi-tlv.c in the Linux kernel. This issue could be exploited to trigger a denial of service.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7042?
CVE-2023-7042 is classified as a denial of service vulnerability that could impact system availability.
How do I fix CVE-2023-7042?
To fix CVE-2023-7042, update the Linux kernel to a version that is not affected, such as 5.10.223-1, 6.1.123-1, or later versions.
What systems are affected by CVE-2023-7042?
CVE-2023-7042 affects multiple versions of the Linux kernel, specifically versions prior to the patches in 5.10.223-1 and 6.1.123-1.
What types of attacks exploit CVE-2023-7042?
CVE-2023-7042 can be exploited to perform denial of service attacks, potentially leading to system crashes.
Is CVE-2023-7042 easy to exploit?
CVE-2023-7042 may be exploited easily if the attacker can send crafted management packets to the vulnerable system.