PT-2019-3601 · Linux+5 · Linux Kernel+5

Nico Waisman

·

Published

2019-07-29

·

Updated

2024-06-15

·

CVE-2019-17666

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.3.6
Description The issue is related to a buffer overflow in the rtl p2p noa ie function in the Linux kernel's rtlwifi driver. This vulnerability can be exploited remotely, allowing an attacker to access confidential data, compromise its integrity, and cause a denial of service. The vulnerability is associated with a lack of a certain upper-bound check, leading to a buffer overflow. It can be exploited by sending specially crafted frames, potentially allowing code execution in the context of the kernel.
Recommendations For Linux kernel versions through 5.3.6, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the rtlwifi driver to minimize the risk of exploitation. Avoid using the rtl p2p noa ie function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but a patch has been proposed by Nicolas Waisman, a security engineer at GitHub.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2321
ALT-PU-2019-2339
ALT-PU-2019-2488
ALT-PU-2019-2746
ALT-PU-2019-3113
ALT-PU-2019-3128
ALT-PU-2019-3136
ALT-PU-2019-3138
ALT-PU-2019-3184
ALT-PU-2020-1024
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-2410
ALT-PU-2020-2433
BDU:2019-03812
CESA-2020_0328
CESA-2020_0339
CESA-2020_0839
CESA-2020_1524
CVE-2019-17666
DLA-2068-1
DLA-2114-1
MGASA-2019-0306
MGASA-2019-0333
OPENSUSE-SU-2019:2392-1
OPENSUSE-SU-2019:2444-1
OPENSUSE-SU-2019_2392-1
OPENSUSE-SU-2019_2444-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:10895-1
OPENSUSE-SU-2024:13704-1
RHSA-2020:0328
RHSA-2020:0339
RHSA-2020:0543
RHSA-2020:0661
RHSA-2020:0740
RHSA-2020:0831
RHSA-2020:0834
RHSA-2020:0839
RHSA-2020:1347
RHSA-2020:1353
RHSA-2020:1465
RHSA-2020:1473
RHSA-2020:1524
RHSA-2020_0328
RHSA-2020_0339
RHSA-2020_0834
RHSA-2020_0839
RHSA-2020_1524
SUSE-SU-2019:2879-1
SUSE-SU-2019:2946-1
SUSE-SU-2019:2947-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2951-1
SUSE-SU-2019:2952-1
SUSE-SU-2019:2953-1
SUSE-SU-2019:2984-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3294-1
SUSE-SU-2019:3295-1
SUSE-SU-2020:0093-1
USN-4183-1
USN-4184-1
USN-4185-1
USN-4186-1
USN-4186-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu