CVE-2024-58096

Aliases:UBUNTU-CVE-2024-58096DEBIAN-CVE-2024-58096CGA-2562-69v7-mqvcCGA-29fc-m84h-mxvrCGA-2fw3-2xw4-cpv7CGA-2gc9-968f-wcmmCGA-2j4f-8x25-4q5wCGA-2m3h-4wv3-86mgCGA-2q63-76vv-q499CGA-2rfm-572v-p2gcCGA-2rwp-r92x-3q9pCGA-2wx7-qwfc-xpfwCGA-3954-257p-2682CGA-39r4-wcg5-vwwrCGA-3frf-99v9-9xhxCGA-3ghp-pfv4-wwmxCGA-3mhm-98vj-gq73CGA-3qq2-q3p4-9jvwCGA-43cq-rm4c-v3qjCGA-4775-qq75-64mwCGA-4f6v-gv36-fxhpCGA-4h37-6ghp-2hhwCGA-5338-vh6g-9gf5CGA-5886-w67c-wm8wCGA-59xp-v4c8-vmjrCGA-5mxw-7j86-vq5hCGA-5p7r-f9vq-fqh4CGA-5ppf-8rvv-x38wCGA-5vq2-2c24-3r2vCGA-6696-73mh-6979CGA-697h-4xq3-gj65CGA-6gf2-mjpx-vcfrCGA-6hwg-5jxw-g8mjCGA-6mfp-x6mj-pqp5CGA-6rg6-h4cr-94q2CGA-6wj3-577x-h49hCGA-6xj8-m6pv-gprrCGA-78q3-8qf7-gp7gCGA-7f9c-j92v-3rmjCGA-7m2h-w4qv-3ffmCGA-7v2m-mq6r-5xw4CGA-826c-3296-553cCGA-85vc-p388-9jm3CGA-8ff7-v76x-359cCGA-8jcw-jm93-w5x6CGA-8m2x-c3gf-v236CGA-9845-9549-27frCGA-99cg-79g6-qgmgCGA-9h2g-g5qv-5ch2CGA-9pvf-j4h2-6hmvCGA-9rm3-5w9g-fp25CGA-c2qc-7v4c-wgw4CGA-c5c4-rvjm-ghr3CGA-c6hr-vm6g-8ppcCGA-c9hg-j7jf-qx47CGA-ccqg-r8q2-cmvwCGA-ccr3-43pg-3wcfCGA-cj73-383m-c4cwCGA-cp9m-rvq8-wqm7CGA-cx43-2gff-9rfwCGA-fhxh-59fp-fp8rCGA-fvhg-94f9-5gv4CGA-fx6c-4r78-9f2vCGA-fxpc-q244-cq4mCGA-g36c-933f-5qp8CGA-g3j5-2xp6-r38mCGA-g5jc-crqp-mfpcCGA-ggh5-w263-9xj2CGA-gh4q-g6w2-vj4qCGA-h337-vq3v-45qpCGA-h7m7-pgr4-35gcCGA-h8fg-hpv7-r2rrCGA-h92x-vpwj-2rx7CGA-h9wx-pv26-xqf2CGA-hcc4-vf9w-xjf8CGA-hf97-gwjm-q65pCGA-hh3v-6894-m8f3CGA-hpcm-xv5w-236jCGA-hx9v-78g6-5mvgCGA-j2gj-w4j4-cxv4CGA-j39p-qc6c-mf7vCGA-j3c2-xg6j-cqj8CGA-j8vm-673p-828rCGA-jf68-7r53-xr9pCGA-jf8p-f68f-w9w2CGA-jg8g-9gj9-m677CGA-jmfq-52ch-x4jvCGA-jp2r-37v8-jqfvCGA-m55v-fcxh-qq72CGA-m5w7-pm8w-vw84CGA-m6g6-frch-mf62CGA-m6wp-frh8-m7h5CGA-m95c-qg34-f9j5CGA-mgqg-3wjv-cw3wCGA-mpr5-m6j2-8gxfCGA-mqwj-9fmq-88wwCGA-mrrh-g564-f2rrCGA-p2rm-25jv-qrr7CGA-p43j-rxgv-xjrxCGA-p73f-57rq-7w3jCGA-p79w-7mhw-36fxCGA-ph4q-gwf6-5vrgCGA-q6h5-2924-557mCGA-q87w-cx2w-q4hhCGA-qfwg-h4fg-3qp2CGA-qgqv-c9jx-83mmCGA-qjgv-p4vw-qp8fCGA-qppx-5w2q-6cp8CGA-qwpx-fhc4-3qwjCGA-r8v8-xc9x-hjc4CGA-rpx4-j743-5457CGA-rrw7-5q59-49r3CGA-rx2h-gm5j-c9cjCGA-v6mf-pv69-x2v5CGA-vgr9-vhhc-fw33CGA-w7c8-7r29-vvf4CGA-w8wj-p3hw-m635CGA-wj6p-vwxq-9gr7CGA-wpjq-6v75-54j6CGA-wv94-46m7-x35gCGA-x4xp-prxx-6p8pCGA-xjfh-vc89-wc8hCGA-xx57-h9p7-78mx
Modified
Published: 16 Apr 2025, 14:11
Last modified:05 Aug 2026, 11:47

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
0.25% LOW
0% probability +0.22%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2025, 14:11
Published
Vulnerability first disclosed
05 Aug 2026, 11:47
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode ath11k_hal_srng_* should be used with srng->lock to protect srng data. For ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(), they use ath11k_hal_srng_* for many times but never call srng->lock. So when running (full) monitor mode, warning will occur: RIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k] Call Trace: ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k] ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k] ? idr_alloc_u32+0x97/0xd0 ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k] ath11k_dp_service_srng+0x289/0x5a0 [ath11k] ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k] __napi_poll+0x30/0x1f0 net_rx_action+0x198/0x320 __do_softirq+0xdd/0x319 So add srng->lock for them to avoid such warnings. Inorder to fetch the srng->lock, should change srng's definition from 'void' to 'struct hal_srng'. And initialize them elsewhere to prevent one line of code from being too long. This is consistent with other ring process functions, such as ath11k_dp_process_rx(). Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1

CVSS Metrics

  • v4.0MEDIUMScore: 5.6CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.25% Percentile: 17%

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.57-r2 | < 6.12.65-r0 | < 6.12.77-r1 | < 6.12.65-r1 | < 6.12.66-r0 | < 6.12.74-r0 | < 6.12.69-r0 | < 6.12.72-r1 | < 6.12.72-r0 | < 6.12.77-r0 | < 6.12.57-r1 | < 6.12.62-r2 | < 6.12.63-r0 | < 6.12.71-r0 | < 6.12.65-r2 | < 6.12.78-r0 | < 6.12.76-r0 | < 6.12.74-r1 | < 6.12.68-r1 | < 6.12.77-r2 | < 6.12.70-r0 | < 6.12.60-r4 | < 6.12.62-r0 | < 6.12.62-r1 | < 6.12.68-r0 | < 6.12.67-r0 | < 6.12.80-r0

  • chainguardlinux-azure-6.12

    < 6.12.65-r2 | < 6.12.60-r3 | < 6.12.57-r1 | < 6.12.74-r0 | < 6.12.68-r0 | < 6.12.65-r3 | < 6.12.62-r2 | < 6.12.62-r1 | < 6.12.77-r2 | < 6.12.69-r0 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.67-r0 | < 6.12.60-r4 | < 6.12.65-r4 | < 6.12.78-r0 | < 6.12.70-r0 | < 6.12.77-r0 | < 6.12.77-r1 | < 6.12.72-r0 | < 6.12.62-r0 | < 6.12.63-r0 | < 6.12.76-r0 | < 6.12.65-r1 | < 6.12.71-r0 | < 6.12.66-r0 | < 6.12.57-r2

  • chainguardlinux-gcp-6.12

    < 6.12.65-r0 | < 6.12.77-r2 | < 6.12.76-r0 | < 6.12.68-r0 | < 6.12.67-r0 | < 6.12.57-r1 | < 6.12.60-r3 | < 6.12.68-r1 | < 6.12.63-r0 | < 6.12.65-r1 | < 6.12.80-r0 | < 6.12.74-r0 | < 6.12.77-r0 | < 6.12.77-r1 | < 6.12.62-r2 | < 6.12.78-r0 | < 6.12.65-r2 | < 6.12.74-r1 | < 6.12.60-r4 | < 6.12.66-r0 | < 6.12.72-r0 | < 6.12.70-r0 | < 6.12.57-r2 | < 6.12.62-r1 | < 6.12.62-r0 | < 6.12.71-r0 | < 6.12.69-r0

  • chainguardlinux-qemu-6.12

    < 6.12.77-r0 | < 6.12.72-r0 | < 6.12.78-r0 | < 6.12.68-r0 | < 6.12.74-r1 | < 6.12.71-r0 | < 6.12.65-r1 | < 6.12.67-r0 | < 6.12.76-r0 | < 6.12.77-r2 | < 6.12.66-r0 | < 6.12.77-r1 | < 6.12.69-r0 | < 6.12.65-r2 | < 6.12.80-r0 | < 6.12.74-r0 | < 6.12.70-r0

  • chainguardlinux-vmware-6.12

    < 6.12.67-r0 | < 6.12.69-r0 | < 6.12.68-r0 | < 6.12.65-r1 | < 6.12.68-r1 | < 6.12.78-r0 | < 6.12.80-r0 | < 6.12.71-r0 | < 6.12.74-r0 | < 6.12.65-r2 | < 6.12.66-r0 | < 6.12.77-r1 | < 6.12.77-r0 | < 6.12.74-r1 | < 6.12.72-r0 | < 6.12.70-r0 | < 6.12.77-r2 | < 6.12.76-r0

  • debianlinux

    all | all | < 6.12.69-1 | < 6.16.3-1

  • ubuntulinux

    all | < 6.8.0-117.117

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 6.8.0-1055.58

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1057.60~22.04.1

  • ubuntulinux-aws-fips

    all | < 6.8.0-1055.58+fips1

  • ubuntulinux-azure

    all | all | < 6.8.0-1056.62

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1059.65~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all | < 6.8.0-1059.65+fips1

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-bluefield

    all | < 6.8.0-1022.26

  • ubuntulinux-fips

    all | < 6.8.0-116.116+fips1

  • ubuntulinux-gcp

    all | all | < 6.8.0-1058.61

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    all

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-6.11

    all

  • ubuntulinux-gcp-6.2

    all

  • ubuntulinux-gcp-6.5

    all

Showing first 50 affected entries in server-rendered view.

References (23)