Skip to main content

CVE-2024-43844: Vulnerability in Linux Linux

High
VulnerabilityCVE-2024-43844cvecve-2024-43844
Published: Sat Aug 17 2024 (08/17/2024, 09:21:58 UTC)
Source: CVE
Vendor/Project: Linux
Product: Linux

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: wow: fix GTK offload H2C skbuff issue We mistakenly put skb too large and that may exceed skb->end. Therefore, we fix it. skbuff: skb_over_panic: text:ffffffffc09e9a9d len:416 put:204 head:ffff8fba04eca780 data:ffff8fba04eca7e0 tail:0x200 end:0x140 dev:<NULL> ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:192! invalid opcode: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 4747 Comm: kworker/u4:44 Tainted: G O 6.6.30-02659-gc18865c4dfbd #1 86547039b47e46935493f615ee31d0b2d711d35e Hardware name: HP Meep/Meep, BIOS Google_Meep.11297.262.0 03/18/2021 Workqueue: events_unbound async_run_entry_fn RIP: 0010:skb_panic+0x5d/0x60 Code: c6 63 8b 8f bb 4c 0f 45 f6 48 c7 c7 4d 89 8b bb 48 89 ce 44 89 d1 41 56 53 41 53 ff b0 c8 00 00 00 e8 27 5f 23 00 48 83 c4 20 <0f> 0b 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 RSP: 0018:ffffaa700144bad0 EFLAGS: 00010282 RAX: 0000000000000089 RBX: 0000000000000140 RCX: 14432c5aad26c900 RDX: 0000000000000000 RSI: 00000000ffffdfff RDI: 0000000000000001 RBP: ffffaa700144bae0 R08: 0000000000000000 R09: ffffaa700144b920 R10: 00000000ffffdfff R11: ffffffffbc28fbc0 R12: ffff8fba4e57a010 R13: 0000000000000000 R14: ffffffffbb8f8b63 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8fba7bd00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007999c4ad1000 CR3: 000000015503a000 CR4: 0000000000350ee0 Call Trace: <TASK> ? __die_body+0x1f/0x70 ? die+0x3d/0x60 ? do_trap+0xa4/0x110 ? skb_panic+0x5d/0x60 ? do_error_trap+0x6d/0x90 ? skb_panic+0x5d/0x60 ? handle_invalid_op+0x30/0x40 ? skb_panic+0x5d/0x60 ? exc_invalid_op+0x3c/0x50 ? asm_exc_invalid_op+0x16/0x20 ? skb_panic+0x5d/0x60 skb_put+0x49/0x50 rtw89_fw_h2c_wow_gtk_ofld+0xbd/0x220 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5] rtw89_wow_resume+0x31f/0x540 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5] rtw89_ops_resume+0x2b/0xa0 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5] ieee80211_reconfig+0x84/0x13e0 [mac80211 818a894e3b77da6298269c59ed7cdff065a4ed52] ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d] ? dev_printk_emit+0x51/0x70 ? _dev_info+0x6e/0x90 ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d] wiphy_resume+0x89/0x180 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d] ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d] dpm_run_callback+0x3c/0x140 device_resume+0x1f9/0x3c0 ? __pfx_dpm_watchdog_handler+0x10/0x10 async_resume+0x1d/0x30 async_run_entry_fn+0x29/0xd0 process_scheduled_works+0x1d8/0x3d0 worker_thread+0x1fc/0x2f0 kthread+0xed/0x110 ? __pfx_worker_thread+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x38/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1b/0x30 </TASK> Modules linked in: ccm 8021q r8153_ecm cdc_ether usbnet r8152 mii dm_integrity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmalloc uinput rfcomm cmac algif_hash rtw89_8922ae(O) algif_skcipher rtw89_8922a(O) af_alg rtw89_pci(O) rtw89_core(O) btusb(O) snd_soc_sst_bxt_da7219_max98357a btbcm(O) snd_soc_hdac_hdmi btintel(O) snd_soc_intel_hda_dsp_common snd_sof_probes btrtl(O) btmtk(O) snd_hda_codec_hdmi snd_soc_dmic uvcvideo videobuf2_vmalloc uvc videobuf2_memops videobuf2_v4l2 videobuf2_common snd_sof_pci_intel_apl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda soundwire_intel soundwire_generic_allocation snd_sof_intel_hda_mlink soundwire_cadence snd_sof_pci snd_sof_xtensa_dsp mac80211 snd_soc_acpi_intel_match snd_soc_acpi snd_sof snd_sof_utils soundwire_bus snd_soc_max98357a snd_soc_avs snd_soc_hda_codec snd_hda_ext_core snd_intel_dspcfg snd_intel_sdw_acpi snd_soc_da7219 snd_hda_codec snd_hwdep snd_hda_core veth ip6table_nat xt_MASQUERADE xt_cgroup fuse bluetooth ecdh_generic cfg80211 ecc gsmi: Log Shutdown ---truncated---

AI-Powered Analysis

AILast updated: 06/29/2025, 07:40:08 UTC

Technical Analysis

CVE-2024-43844 is a vulnerability identified in the Linux kernel specifically related to the Realtek rtw89 wireless driver, which handles Wi-Fi functionality. The flaw arises in the handling of GTK (Group Temporal Key) offload in the Wake-on-Wireless (WoW) feature, where the driver mistakenly allocates a socket buffer (skb) that is too large, potentially exceeding the skb->end boundary. This causes a kernel panic due to an out-of-bounds memory access, as indicated by the skb_over_panic error and the kernel BUG at net/core/skbuff.c. The vulnerability is triggered during the processing of H2C (Host to Chip) commands related to GTK offload in the rtw89 driver, which is part of the wireless networking stack. The kernel panic leads to a denial of service (DoS) condition, crashing the affected system or causing instability. The detailed kernel stack trace shows the panic occurs in skb_panic, triggered by skb_put when the skb buffer boundaries are violated. The issue affects Linux kernel version 6.6.30-02659-gc18865c4dfbd and likely other versions using the vulnerable rtw89 driver. The vulnerability does not appear to have known exploits in the wild yet, and no CVSS score has been assigned. However, the impact is significant as it can cause system crashes on devices using the affected wireless driver, which is common in many Linux-based systems including laptops, desktops, and embedded devices. The root cause is a programming error in buffer size management within the wireless driver’s WoW GTK offload implementation, which has been fixed by correcting the skb allocation size to prevent overflow.

Potential Impact

For European organizations, the impact of CVE-2024-43844 can be substantial, especially for those relying on Linux-based systems with Realtek rtw89 wireless hardware. The vulnerability can cause unexpected system crashes and denial of service, disrupting business operations, network connectivity, and potentially causing data loss or corruption if systems reboot unexpectedly. Organizations with critical infrastructure, enterprise networks, or cloud services running Linux kernels with this driver are at risk of operational downtime. The DoS condition could be exploited by an attacker with local access or potentially via crafted wireless frames if the device processes such packets while in WoW mode. This could affect endpoint devices, servers, or embedded systems in industrial or IoT environments. The disruption of wireless connectivity can degrade productivity and impact remote work capabilities, which are prevalent in Europe. Additionally, the instability caused by kernel panics may complicate incident response and system maintenance. Although no remote code execution or privilege escalation is indicated, the denial of service alone warrants urgent attention to prevent operational impact.

Mitigation Recommendations

European organizations should prioritize updating their Linux kernels to versions where this vulnerability is patched. Specifically, they should apply the latest stable kernel releases that include the fix for the rtw89 driver’s GTK offload skb allocation issue. System administrators should audit their environments to identify devices using the rtw89 wireless driver and verify kernel versions. If immediate patching is not feasible, disabling the WoW GTK offload feature or the WoW functionality for the rtw89 device can serve as a temporary mitigation to prevent triggering the vulnerability. Network segmentation and limiting local access to critical Linux systems can reduce the risk of exploitation. Monitoring kernel logs for skb_over_panic or related errors can help detect attempts to trigger the flaw. For embedded or IoT devices, coordinate with vendors to obtain firmware or kernel updates. Additionally, organizations should review wireless device configurations to minimize exposure to untrusted wireless frames, especially in sensitive environments. Implementing robust patch management processes and maintaining up-to-date inventories of Linux kernel versions and wireless drivers will aid in rapid response to such vulnerabilities.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.1
Assigner Short Name
Linux
Date Reserved
2024-08-17T09:11:59.275Z
Cisa Enriched
true
Cvss Version
null
State
PUBLISHED

Threat ID: 682d9828c4522896dcbe2055

Added to database: 5/21/2025, 9:08:56 AM

Last enriched: 6/29/2025, 7:40:08 AM

Last updated: 8/1/2025, 7:25:54 AM

Views: 10

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats