{"id":"DEBIAN-CVE-2024-56609","details":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: use ieee80211_purge_tx_queue() to purge TX skb  When removing kernel modules by:    rmmod rtw88_8723cs rtw88_8703b rtw88_8723x rtw88_sdio rtw88_core  Driver uses skb_queue_purge() to purge TX skb, but not report tx status causing \"Have pending ack frames!\" warning. Use ieee80211_purge_tx_queue() to correct this.  Since ieee80211_purge_tx_queue() doesn't take locks, to prevent racing between TX work and purge TX queue, flush and destroy TX work in advance.     wlan0: deauthenticating from aa:f5:fd:60:4c:a8 by local      choice (Reason: 3=DEAUTH_LEAVING)    ------------[ cut here ]------------    Have pending ack frames!    WARNING: CPU: 3 PID: 9232 at net/mac80211/main.c:1691        ieee80211_free_ack_frame+0x5c/0x90 [mac80211]    CPU: 3 PID: 9232 Comm: rmmod Tainted: G         C        6.10.1-200.fc40.aarch64 #1    Hardware name: pine64 Pine64 PinePhone Braveheart       (1.1)/Pine64 PinePhone Braveheart (1.1), BIOS 2024.01 01/01/2024    pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)    pc : ieee80211_free_ack_frame+0x5c/0x90 [mac80211]    lr : ieee80211_free_ack_frame+0x5c/0x90 [mac80211]    sp : ffff80008c1b37b0    x29: ffff80008c1b37b0 x28: ffff000003be8000 x27: 0000000000000000    x26: 0000000000000000 x25: ffff000003dc14b8 x24: ffff80008c1b37d0    x23: ffff000000ff9f80 x22: 0000000000000000 x21: 000000007fffffff    x20: ffff80007c7e93d8 x19: ffff00006e66f400 x18: 0000000000000000    x17: ffff7ffffd2b3000 x16: ffff800083fc0000 x15: 0000000000000000    x14: 0000000000000000 x13: 2173656d61726620 x12: 6b636120676e6964    x11: 0000000000000000 x10: 000000000000005d x9 : ffff8000802af2b0    x8 : ffff80008c1b3430 x7 : 0000000000000001 x6 : 0000000000000001    x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000    x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000003be8000    Call trace:     ieee80211_free_ack_frame+0x5c/0x90 [mac80211]     idr_for_each+0x74/0x110     ieee80211_free_hw+0x44/0xe8 [mac80211]     rtw_sdio_remove+0x9c/0xc0 [rtw88_sdio]     sdio_bus_remove+0x44/0x180     device_remove+0x54/0x90     device_release_driver_internal+0x1d4/0x238     driver_detach+0x54/0xc0     bus_remove_driver+0x78/0x108     driver_unregister+0x38/0x78     sdio_unregister_driver+0x2c/0x40     rtw_8723cs_driver_exit+0x18/0x1000 [rtw88_8723cs]     __do_sys_delete_module.isra.0+0x190/0x338     __arm64_sys_delete_module+0x1c/0x30     invoke_syscall+0x74/0x100     el0_svc_common.constprop.0+0x48/0xf0     do_el0_svc+0x24/0x38     el0_svc+0x3c/0x158     el0t_64_sync_handler+0x120/0x138     el0t_64_sync+0x194/0x198    ---[ end trace 0000000000000000 ]---","modified":"2026-09-15T09:02:59.955616774Z","published":"2024-12-27T15:15:20.387Z","upstream":["CVE-2024-56609"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56609"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.137-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56609.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56609.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56609.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}