CVE-2024-35838
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-35838 affects the Linux kernel's mac80211 subsystem, specifically related to station link management. The vulnerability was discovered and disclosed on May 17, 2024, and involves a potential memory leak in the WiFi stack when handling station allocation and link management. The issue affects various Linux kernel versions that implement the mac80211 subsystem (Kernel Git).

Technical details

The vulnerability occurs in the station link management code of the mac80211 subsystem. When a station is allocated, links are added but not set to valid yet (e.g., during connection to an AP MLD). In certain scenarios, the station might be removed without ever marking these links as valid, leading to a memory leak. The issue stems from a bug in the sta_info_free function where the link removal logic incorrectly checked for valid links instead of allocated links (Kernel Git).

Impact

The vulnerability can result in memory leaks in the Linux kernel's WiFi stack, potentially leading to resource exhaustion over time. This could affect system stability and performance on affected systems using WiFi connectivity (NVD).

Exploitability

The vulnerability requires local access to a system using the affected WiFi stack components. There are no known reports of this vulnerability being exploited in the wild (NVD).

Mitigation and workarounds

A fix has been implemented and is available in various Linux distributions. Ubuntu has released patches for affected versions, including fixes for Ubuntu 23.10 (linux 6.5.0-41.41), Ubuntu 22.04 LTS (linux-hwe 6.5.0-41.41~22.04.2), and several other packages (Ubuntu). The fix involves modifying the sta_info_free function to properly check for allocated links rather than valid links (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management