CVE-2024-53189: wifi: nl80211: fix bounds checker error in nl80211_parse_sched_scan

Published Dec 27, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: nl80211: fix bounds checker error in nl80211parseschedscan

The channels array in the cfg80211scanrequest has a countedby attribute attached to it, which points to the nchannels variable. This attribute is used in bounds checking, and if it is not set before the array is filled, then the bounds sanitizer will issue a warning or a kernel panic if CONFIGUBSANTRAP is set.

This patch sets the size of allocated memory as the initial value for nchannels. It is updated with the actual number of added elements after the array is filled.

Affected Software

4 affected componentsFixes available
Linux Linux kernel
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Linux Linux kernel>=6.11<6.11.11
Linux Linux kernel>=6.12<6.12.2

Event History

Dec 27, 2024
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
Description
Data Sourced
via NVD·02:15 PM
Description
Data Sourced
via NVD·02:15 PM
RemedySeverityAffected Software
Apr 1, 2025
Data Sourced
via Ubuntu·01:03 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-53189?

CVE-2024-53189 has a severity rating that reflects potential impacts on system stability and security due to the bounds checker error.

2

How do I fix CVE-2024-53189?

To fix CVE-2024-53189, upgrade to the latest patched versions of the Linux kernel or use the specified versions including 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.15-1.

3

What products are affected by CVE-2024-53189?

CVE-2024-53189 affects the Linux kernel across various distributions that included vulnerable versions.

4

Is there a workaround for CVE-2024-53189?

There are no known workarounds for CVE-2024-53189; applying the patch is strongly recommended.

5

What is the nature of the vulnerability described in CVE-2024-53189?

CVE-2024-53189 is a bounds checker error that can affect the reliability of the wireless scanning process in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203