Junglewise Threat Intelligence

CVE-2024-40912: Linux Kernel mac80211 deadlock in ieee80211_sta_ps_deliver_wakeup

CVE-2024-40912 · Severity: medium · CVSS 5.5 · Published 2024-07-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Wi-Fi stack could allow a local attacker to cause a system deadlock, leading to a complete service outage (denial of service). The issue occurs in the mac80211 framework, which manages wireless networking operations. An exploit would result in the system becoming unresponsive, requiring a hard reboot and potentially disrupting network connectivity and business operations.

Technical details

A deadlock exists in the mac80211 subsystem within the ieee80211_sta_ps_deliver_wakeup() function. The root cause is the use of spin_lock() instead of spin_lock_bh() when acquiring sta->ps_lock. Because ieee80211_tx_h_unicast_ps_buf() can be called from a softirq context on the same CPU, it may attempt to acquire the same lock already held by the wakeup function, resulting in a circular dependency and an RCU stall. An attacker with local access could trigger this condition to cause a kernel panic or system hang. The issue has been resolved by switching to bottom-half-safe locking primitives (spin_lock_bh).

Affected products

  • Linux Linux Kernel 3.14 to 4.19.317, 5.4.279, 5.10.221, 5.15.162, 6.1.96, 6.6.36, 6.9.7

Timeline

  • 2024-05-29: patched: Initial fix developed and signed off by maintainers.
  • 2024-07-12: advisory: CVE-2024-40912 published.

References

Related threats