SB20250227123 - Improper locking in Linux kernel realtek rtw89 driver
Published: February 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2024-57991)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the rtw89_entity_recalc_mgnt_roles() function in drivers/net/wireless/realtek/rtw89/chan.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01d2d34e9fcc9897081c3c16a666f793c8a38c58
- https://git.kernel.org/stable/c/223ba95fdcd3c6090e2bd51dce66abb6dd4f9df9
- https://git.kernel.org/stable/c/e4790b3e314a4814f1680a5dc552031fb199b878
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14