LiveActive security incident?Get immediate response
CVE Record

CVE-2024-50235: wifi: cfg80211: clear wdev->cqm_config pointer on free

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear wdev->cqm_config pointer on free When we free wdev->cqm_config when unregistering, we also need to clear out the pointer since the same wdev/netdev may get re-registered in another network namespace, then destroyed later, running this code again, which results in a double-free.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux Wi-Fi subsystem cleanup bug can free the same memory twice when a wireless device is unregistered, re-registered in another network namespace, and later destroyed. This may crash the kernel or corrupt privileged kernel memory. The supplied CVSS score is 7.8 High and requires local, low-privilege access; it is not described as a remote attack.

Executive priority

Prioritize an expedited kernel update on systems permitting low-privilege local access and wireless-device namespace operations. Validate vendor backports before declaring exposure from version numbers. The potential impact is high, but the supplied evidence does not support treating this as an actively exploited or internet-facing emergency.

Technical view

During wireless device unregistration, cfg80211 frees wdev->cqm_config but fails to clear the pointer. Reusing the same wdev/netdev in another network namespace leaves the stale pointer available for a second free during later destruction. The stable changes clear the pointer after freeing it, addressing CWE-415.

Likely exposure

Exposure requires a Linux kernel containing the vulnerable cfg80211 behavior, relevant wireless-device lifecycle activity, and local reachability. The bundled version data mixes baselines, endpoints, and commit identifiers, so version strings alone are insufficient. Confirm exposure using distribution backport records and the cited stable fixes.

Exploitation context

The bundle's KEV flag is false and contains no cited evidence of active exploitation or public weaponization. The CVSS vector specifies local access, low complexity, low privileges, and no user interaction. Kernel memory corruption could have serious consequences, but reliable privilege escalation is not demonstrated by the supplied sources.

Researcher notes

The correction addresses stale pointer state rather than merely changing allocation timing. Although the CVSS models complete confidentiality, integrity, and availability impact, the supplied sources do not establish a reliable privilege-escalation path. Analyze reachability through wdev/netdev re-registration and map distribution backports carefully; do not assume every kernel within a broad 6.x line is vulnerable.

Mitigation direction

  • Apply a supported distribution kernel containing the applicable stable fix, following vendor guidance.
  • Reboot into the updated kernel; installing a package alone does not remediate the running kernel.
  • Track distribution advisories because vendors may backport fixes without adopting upstream version numbers.
  • Until updated, limit untrusted local access and unnecessary network-namespace operations where operationally feasible.

Validation and detection

  • Record the running kernel build, not only installed kernel package versions.
  • Verify distribution changelogs or kernel sources contain the applicable cited stable correction.
  • Confirm the system rebooted into the remediated kernel build.
  • Determine whether cfg80211 wireless functionality and low-privilege local access are present.
  • Review kernel crash records for cfg80211 or double-free faults; their absence does not prove safety.
Prepared
Confidence
medium
Sources
7

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-415: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-50235 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
2ADP providers
6Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2024-50235Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxc797498e860e9a435a651bbf0789433684ce6dd8, 37c20b2effe987b806c8de6d12978e4ffeff026f, 37c20b2effe987b806c8de6d12978e4ffeff026f, 37c20b2effe987b806c8de6d12978e4ffeff026f, 32fb9b7d98c3e586bddfb978d383aa8d2b1211bc, 6.1.57, 6.5.7unaffected
LinuxLinux6.6, 0, 6.1.116, 6.6.60, 6.11.7, 6.12affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-415 · source CWE mapping

Double Free

Double Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.