Security Vulnerabilities
- CVEs Published In August 2024
Memory corruption while allocating memory in HGSL driver.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
Transient DOS while parsing the received TID-to-link mapping action frame.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.