CVE-2024-49857: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: set the cipher for secured NDP ranging The cipher pointer is not set, but is derefereced trying to set its content, which leads to a NULL pointer dereference. Fix it by pointing to the cipher parameter before dereferencing.

Affected products

  • Linux Linux Kernel: from 6.11, before 6.11.2 (fixed in 6.11.2)

Published 2024-10-21. Last modified 2026-08-04.