Skip to main content
EPSS 0.3%top 83%

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix kernel crash during resume Currently during resume, QMI target… (CVE-2024-40979)

0
Medium
Published: 07/12/2024 (07/12/2024, 15:31:29 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's ath12k Wi-Fi driver caused a kernel crash during system resume due to improper handling of QMI target memory when DMA remap is not supported. The issue arises from a mismatch in memory segment sizes during allocation and freeing, leading to freeing memory still in use and causing a crash. This vulnerability has been resolved in the Linux kernel.

CVSS v3.1

Score 5.5medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:24:03 UTC

Technical Analysis

The Linux kernel's ath12k Wi-Fi driver improperly handles QMI target memory during resume when DMA remap is unsupported. Initially, firmware requests large memory segments which fail allocation, then retries with smaller segments that succeed. Upon resume, firmware again requests large segments, but allocation fails and partial freeing of memory segments occurs. Due to a mismatch between the expected and actual sizes of memory segments during freeing, the kernel attempts to free memory still in use, causing a crash. This issue has been fixed in the Linux kernel.

Potential Impact

This vulnerability causes a kernel crash (denial of service) during system resume on affected systems using the ath12k Wi-Fi driver when DMA remap is not supported. There is no indication of confidentiality or integrity impact.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to properly handle QMI target memory during resume, preventing the kernel crash. Users should update their Linux kernel to a version that includes this fix. Patch status is not explicitly stated in the input, so verify the vendor advisory for the exact fixed kernel versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-gvwx-6cpm-mjrj
Osv Schema Version
1.4.0
Aliases
["CVE-2024-40979"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac13969a43b0b3b89d5fbb3

Added to database: 10/03/2026, 17:20:41 UTC

Last enriched: 10/03/2026, 17:24:03 UTC

Last updated: 10/04/2026, 03:08:42 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses