CVE-2024-35789: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's netdev, which can cause use-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx after the VLAN change.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.14.232, before 4.15 (fixed in 4.15); from 4.19.189, before 4.19.312 (fixed in 4.19.312); from 5.4.114, before 5.4.274 (fixed in 5.4.274); from 5.10.32, before 5.10.215 (fixed in 5.10.215); from 5.11.16, before 5.12 (fixed in 5.12); from 5.12.1, before 5.15.154 (fixed in 5.15.154); …

Published 2024-05-17. Last modified 2026-08-04.