---
id: CVE-2024-35937
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: cfg80211: check A-MSDU format more carefully

  If it looks like there's another subframe in the A-MSDU
  but the header isn't fully there, we can end up reading
  data…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: cfg80211: check A-MSDU format more carefully

  If it looks like there's another subframe in the A-MSDU
  but the header isn't fully there, we can end up reading
  data…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: debian
product: debian_linux
affected:
  - debian_linux = 11.0
  - 'linux_kernel >= 6.3, < 6.6.27'
  - 'linux_kernel >= 6.7, < 6.8.6'
patched:
  - linux_kernel 6.8.6
published: '2024-05-19'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T18:21:56.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-35937'
references:
  - url: 'https://git.kernel.org/stable/c/16da1e1dac23be45ef6e23c41b1508c400e6c544'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5d7a8585fbb31e88fb2a0f581b70667d3300d1e9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9ad7974856926129f190ffbe3beea78460b3b7cc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9eb3bc0973d084423a6df21cf2c74692ff05647e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/16da1e1dac23be45ef6e23c41b1508c400e6c544'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/5d7a8585fbb31e88fb2a0f581b70667d3300d1e9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/9ad7974856926129f190ffbe3beea78460b3b7cc'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00344
epssPercentile: 0.25827
ingestedAt: '2026-10-08T18:58:11.292Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: check A-MSDU format more carefully

If it looks like there's another subframe in the A-MSDU
but the header isn't fully there, we can end up reading
data out of bounds, only to discard later. Make this a
bit more careful and check if the subframe header can
even be present.

## Affected

- `debian_linux = 11.0`
- `linux_kernel >= 6.3, < 6.6.27`
- `linux_kernel >= 6.7, < 6.8.6`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.8.6`
