In the Linux kernel, the following vulnerability has been resolved:
wifi: wcn36xx: fix channel survey memory allocation size
KASAN reported a memory allocation issue in wcn->chan_survey
due to incorrect size calculation.
This commit uses kcalloc to allocate memory for wcn->chan_survey,
ensuring proper initialization and preventing the use of uninitialized
values when there are no frames on the channel.
Security readout for executives and security teams
Plain-English summary
CVE-2024-57997 is a Linux kernel Wi-Fi driver bug in wcn36xx. A memory allocation size mistake could lead to use of uninitialized values and a kernel availability impact. The public scoring indicates local, low-privilege access is required. There is no cited evidence of active exploitation.
Executive priority
Treat as routine-to-priority patching for Linux endpoints or embedded devices using affected Wi-Fi hardware. It is not supported by public evidence as internet-remote or actively exploited, but availability impact in the kernel warrants timely remediation where exposure exists.
Technical view
The wcn36xx channel survey allocation used an incorrect size calculation for wcn->chan_survey. Kernel KASAN reported the issue. The fix changes allocation to kcalloc, ensuring correct sizing and initialization when there are no frames on the channel. CVSS 3.1 is 5.5: local, low complexity, low privileges, availability impact only.
Likely exposure
Exposure is most relevant to Linux systems running affected kernel versions with the wcn36xx Wi-Fi driver present or used. Servers without this driver or hardware are less likely to be exposed. Confirm exposure through kernel version, distribution advisories, and driver/module inventory.
Exploitation context
Public sources do not state active exploitation, and it is not listed as CISA KEV in the provided data. The CVSS vector indicates local access with low privileges is required. The documented impact is availability, not confidentiality or integrity.
Researcher notes
The affected-version data in the source bundle is not fully intuitive and should be reconciled against distribution kernel advisories. The core fix is in Linux stable commits for wcn36xx allocation behavior. Avoid assuming exposure without confirming the driver and vendor backport status.
Mitigation direction
Update to a vendor or distribution kernel containing the referenced stable fixes.
For Debian LTS systems, review and apply the cited Debian security update.
Prioritize systems using wcn36xx Wi-Fi hardware or loading the wcn36xx driver.
If no vendor package is available, monitor vendor guidance before applying custom kernels.
Validation and detection
Inventory Linux kernel versions across endpoints and embedded systems.
Check whether the wcn36xx driver is present, loaded, or tied to installed hardware.
Compare installed kernels with vendor advisories and referenced stable commit coverage.
After updating, verify the patched kernel is running following reboot.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-908: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-908 · source CWE mapping
Use of Uninitialized Resource
Use of Uninitialized Resource represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.