CVE-2024-26683

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26683
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26683.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-26683
Downstream
Related
Published
2024-04-02T07:01:45Z
Modified
2025-10-21T18:44:59.207792Z
Summary
wifi: cfg80211: detect stuck ECSA element in probe resp
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: detect stuck ECSA element in probe resp

We recently added some validation that we don't try to connect to an AP that is currently in a channel switch process, since that might want the channel to be quiet or we might not be able to connect in time to hear the switching in a beacon. This was in commit c09c4f31998b ("wifi: mac80211: don't connect to an AP while it's in a CSA process").

However, we promptly got a report that this caused new connection failures, and it turns out that the AP that we now cannot connect to is permanently advertising an extended channel switch announcement, even with quiet. The AP in question was an Asus RT-AC53, with firmware 3.0.0.4.380_10760-g21a5898.

As a first step, attempt to detect that we're dealing with such a situation, so mac80211 can use this later.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c09c4f31998bac6d73508e38812518aceb069b68
Fixed
ce112c941c2b172afba3e913a90c380647d53975
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c09c4f31998bac6d73508e38812518aceb069b68
Fixed
177fbbcb4ed6b306c1626a277fac3fb1c495a4c7

Affected versions

v6.*

v6.5
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.7.1
v6.7.2
v6.7.3
v6.7.4
v6.8-rc1

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.5