PT-2017-4236 · Linux+5 · Linux Kernel+5

Freenerguo

+1

·

Published

2017-07-12

·

Updated

2024-06-15

·

CVE-2017-7541

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.3
Description The issue is related to a buffer overflow in the brcmf cfg80211 mgmt tx function. This can be exploited to cause a denial of service, resulting in a system crash, or potentially to gain privileges. The exploitation involves a crafted NL80211 CMD FRAME Netlink packet.
Recommendations For Linux kernel versions prior to 4.12.3, update to version 4.12.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the brcmf cfg80211 mgmt tx function in the cfg80211.c module to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1952
ALT-PU-2017-1967
BDU:2023-00939
CESA-2017_2863
CESA-2017_2930
CVE-2017-7541
DSA-3927-1
DSA-3945-1
OPENSUSE-SU-2017_2110-1
OPENSUSE-SU-2017_2112-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2017:2863
RHSA-2017:2918
RHSA-2017:2930
RHSA-2017:2931
RHSA-2017_2863
RHSA-2017_2930
RHSA-2017_2931
SUSE-SU-2017:2286-1
SUSE-SU-2017:2869-1
SUSE-SU-2017:2908-1
SUSE-SU-2017:2920-1
SUSE-SU-2017:2956-1
USN-3405-1
USN-3405-2
USN-3419-1
USN-3419-2
USN-3422-1
USN-3422-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu