CVE-2024-43912: wifi: nl80211: disallow setting special AP channel widths
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: disallow setting special AP channel widths
Setting the AP channel width is meant for use with the normal
20/40/... MHz channel width progression, and switching around
in S1G or narrow channels isn't supported. Disallow that.
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue restricts unsupported Wi-Fi access point channel-width changes. The public sources do not describe business impact, active exploitation, or a CVSS score. Treat it as a kernel maintenance item, with higher attention for systems using Linux wireless access point functionality.
Executive priority
Handle through normal kernel patch governance unless wireless AP infrastructure is business-critical. There is no supplied evidence of active exploitation or severe impact, but affected Linux wireless roles should be patched promptly.
Technical view
CVE-2024-43912 concerns Linux kernel nl80211 handling of AP channel width settings. The fix disallows special S1G or narrow-channel width changes where only normal 20/40 MHz-style progression is supported. Public data lists affected Linux kernel versions and stable commits, but not exploitability or impact details.
Likely exposure
Exposure is most plausible on Linux systems using Wi-Fi access point or nl80211-managed wireless functionality. General servers without wireless hardware or AP roles are likely lower priority, but kernel package applicability should still be verified through distribution advisories.
Exploitation context
CISA KEV is false in the supplied bundle, and no cited source reports active exploitation. The sources provide fix references but do not provide exploit prerequisites, demonstrated attacks, or practical abuse conditions.
Researcher notes
The source bundle lacks CVSS, CWE, and impact analysis. Research should focus on the referenced stable commits, affected kernel ranges, and whether local configuration paths can trigger unsupported AP channel-width transitions.
Mitigation direction
Update Linux kernels to vendor-supported releases that include the referenced stable fixes.
Apply Debian LTS kernel updates where Debian systems are in scope.
Prioritize systems operating Wi-Fi AP or nl80211-managed wireless functionality.
Monitor Linux distribution advisories for backported kernel packages.
Follow vendor guidance where fixed package versions differ from upstream kernel numbers.
Validation and detection
Inventory Linux kernel versions on systems with wireless interfaces or AP functionality.
Confirm installed kernel packages include fixes for CVE-2024-43912.
Review kernel changelogs for the referenced nl80211 AP channel-width fix.
Check Debian LTS advisory applicability for Debian LTS hosts.
Record systems without wireless capability as lower exposure, pending vendor guidance.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-43912 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.