{"id":"DEBIAN-CVE-2024-43911","details":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: fix NULL dereference at band check in starting tx ba session  In MLD connection, link_data/link_conf are dynamically allocated. They don't point to vif-\u003ebss_conf. So, there will be no chanreq assigned to vif-\u003ebss_conf and then the chan will be NULL. Tweak the code to check ht_supported/vht_supported/has_he/has_eht on sta deflink.  Crash log (with rtw89 version under MLO development): [ 9890.526087] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 9890.526102] #PF: supervisor read access in kernel mode [ 9890.526105] #PF: error_code(0x0000) - not-present page [ 9890.526109] PGD 0 P4D 0 [ 9890.526114] Oops: 0000 [#1] PREEMPT SMP PTI [ 9890.526119] CPU: 2 PID: 6367 Comm: kworker/u16:2 Kdump: loaded Tainted: G           OE      6.9.0 #1 [ 9890.526123] Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB3WW (2.73 ) 11/28/2018 [ 9890.526126] Workqueue: phy2 rtw89_core_ba_work [rtw89_core] [ 9890.526203] RIP: 0010:ieee80211_start_tx_ba_session (net/mac80211/agg-tx.c:618 (discriminator 1)) mac80211 [ 9890.526279] Code: f7 e8 d5 93 3e ea 48 83 c4 28 89 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 49 8b 84 24 e0 f1 ff ff 48 8b 80 90 1b 00 00 \u003c83\u003e 38 03 0f 84 37 fe ff ff bb ea ff ff ff eb cc 49 8b 84 24 10 f3 All code ========    0:\tf7 e8                \timul   %eax    2:\td5                   \t(bad)    3:\t93                   \txchg   %eax,%ebx    4:\t3e ea                \tds (bad)    6:\t48 83 c4 28          \tadd    $0x28,%rsp    a:\t89 d8                \tmov    %ebx,%eax    c:\t5b                   \tpop    %rbx    d:\t41 5c                \tpop    %r12    f:\t41 5d                \tpop    %r13   11:\t41 5e                \tpop    %r14   13:\t41 5f                \tpop    %r15   15:\t5d                   \tpop    %rbp   16:\tc3                   \tretq   17:\tcc                   \tint3   18:\tcc                   \tint3   19:\tcc                   \tint3   1a:\tcc                   \tint3   1b:\t49 8b 84 24 e0 f1 ff \tmov    -0xe20(%r12),%rax   22:\tff   23:\t48 8b 80 90 1b 00 00 \tmov    0x1b90(%rax),%rax   2a:*\t83 38 03             \tcmpl   $0x3,(%rax)\t\t\u003c-- trapping instruction   2d:\t0f 84 37 fe ff ff    \tje     0xfffffffffffffe6a   33:\tbb ea ff ff ff       \tmov    $0xffffffea,%ebx   38:\teb cc                \tjmp    0x6   3a:\t49                   \trex.WB   3b:\t8b                   \t.byte 0x8b   3c:\t84 24 10             \ttest   %ah,(%rax,%rdx,1)   3f:\tf3                   \trepz  Code starting with the faulting instruction ===========================================    0:\t83 38 03             \tcmpl   $0x3,(%rax)    3:\t0f 84 37 fe ff ff    \tje     0xfffffffffffffe40    9:\tbb ea ff ff ff       \tmov    $0xffffffea,%ebx    e:\teb cc                \tjmp    0xffffffffffffffdc   10:\t49                   \trex.WB   11:\t8b                   \t.byte 0x8b   12:\t84 24 10             \ttest   %ah,(%rax,%rdx,1)   15:\tf3                   \trepz [ 9890.526285] RSP: 0018:ffffb8db09013d68 EFLAGS: 00010246 [ 9890.526291] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff9308e0d656c8 [ 9890.526295] RDX: 0000000000000000 RSI: ffffffffab99460b RDI: ffffffffab9a7685 [ 9890.526300] RBP: ffffb8db09013db8 R08: 0000000000000000 R09: 0000000000000873 [ 9890.526304] R10: ffff9308e0d64800 R11: 0000000000000002 R12: ffff9308e5ff6e70 [ 9890.526308] R13: ffff930952500e20 R14: ffff9309192a8c00 R15: 0000000000000000 [ 9890.526313] FS:  0000000000000000(0000) GS:ffff930b4e700000(0000) knlGS:0000000000000000 [ 9890.526316] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 9890.526318] CR2: 0000000000000000 CR3: 0000000391c58005 CR4: 00000000001706f0 [ 9890.526321] Call Trace: [ 9890.526324]  \u003cTASK\u003e [ 9890.526327] ? show_regs (arch/x86/kernel/dumpstack.c:479) [ 9890.526335] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434) [ 9890.526340] ? page_fault_oops (arch/x86/mm/fault.c:713) [ 9890.526347] ? search_module_extables (kernel/module/main.c:3256 (discriminator ---truncated---","modified":"2026-09-15T09:03:10.762604638Z","published":"2024-08-26T11:15:05.227Z","upstream":["CVE-2024-43911"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-43911"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-43911.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-43911.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}