Security readout for executives and security teams
Plain-English summary
A Linux Intel Wi-Fi driver flaw can misinterpret a firmware notification and trigger kernel warnings. The supplied CVSS assessment indicates a nearby, unauthenticated attacker could potentially affect system availability and limited integrity without user action. Servers without affected Intel wireless hardware or the iwlwifi stack are unlikely to be exposed.
Executive priority
Prioritize normal high-severity patching for wireless Linux endpoints, especially mobile systems exposed to nearby networks. This is not supported as an emergency, internet-wide threat because exploitation requires adjacent access and no active exploitation is documented. Accelerate remediation if affected systems show kernel warnings or availability problems.
Technical view
The iwlwifi MVM code selected mac_id versus link_id using the wrong version context for SESSION_PROTECTION_NOTIF. This can cause warnings in iwl_mvm_rx_session_protect_notif during interrupt-driven receive processing. The kernel fixes select the notification layout using the SESSION_PROTECTION_NOTIF version.
Likely exposure
Exposure requires an affected Linux kernel and use of the Intel iwlwifi MVM wireless path. The bundle identifies affected 6.7-era ranges with boundaries involving 6.8.5 and 6.9, but its flattened version data is ambiguous. Confirm distribution backports rather than relying only on version numbers.
Exploitation context
CISA KEV status is false, and the supplied sources do not establish active exploitation or a public exploit. CVSS 3.1 rates it 7.1 with adjacent-network access, low complexity, no privileges, and no user interaction. Treat exploitability beyond those characteristics as unconfirmed.
Researcher notes
The observable symptom supplied is a kernel WARNING in the session-protection notification handler. The CVSS vector claims high availability and low integrity impact, but the bundle does not describe demonstrated exploitation, crash reliability, or an attack primitive. Exact affected-range interpretation should be validated against kernel or distribution advisories.
Mitigation direction
Install a vendor-supported kernel containing the applicable stable fix or backport.
Check distribution security guidance for the exact fixed package version.
Prioritize laptops and endpoints actively using affected Intel Wi-Fi hardware.
Where updates are delayed, reduce reliance on affected wireless interfaces when operationally practical.
Validation and detection
Inventory Linux versions, Intel wireless hardware, and loaded iwlwifi or iwlmvm modules.
Verify the installed kernel includes either cited stable fix or the distribution's equivalent backport.
Review kernel logs for warnings from iwl_mvm_rx_session_protect_notif.
After updating, exercise normal Wi-Fi operations and confirm warnings do not recur.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-35913 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.