PT-2019-4201 · Linux+4 · Linux Kernel+4

Dhananjay Arunesh

·

Published

2019-11-25

·

Updated

2024-06-15

·

CVE-2019-14896

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel version kernel-2.6.32
Description A heap-based buffer overflow vulnerability was found in the Linux kernel's Marvell WiFi chip driver. This issue is related to the lbs ibss join existing function and the add ie rates function in the drivers/net/wireless/marvell/libertas/cfg.c file. A remote attacker could cause a denial of service (system crash) or possibly execute arbitrary code when the lbs ibss join existing function is called after a STA connects to an AP. The vulnerability also allows an attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For Linux kernel version kernel-2.6.32, consider disabling the lbs ibss join existing function and restricting access to the add ie rates function in the drivers/net/wireless/marvell/libertas/cfg.c file as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1122
ALT-PU-2020-1131
ALT-PU-2020-1140
ALT-PU-2020-1147
ALT-PU-2020-1161
ALT-PU-2020-1189
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1524
ALT-PU-2020-1714
ALT-PU-2020-1945
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2020-3057
ALT-PU-2021-1745
BDU:2019-04798
CVE-2019-14896
DLA-2068-1
DLA-2114-1
MGASA-2020-0073
MGASA-2020-0089
OPENSUSE-SU-2020:0336-1
OPENSUSE-SU-2020_0336-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2020:3548
RHSA-2020_3548
SUSE-SU-2020:0183-1
SUSE-SU-2020:0204-1
SUSE-SU-2020:0511-1
SUSE-SU-2020:0558-1
SUSE-SU-2020:0559-1
SUSE-SU-2020:0560-1
SUSE-SU-2020:0580-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0605-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020:1275-1
SUSE-SU-2020:14354-1
SUSE-SU-2020:1663-1
SUSE-SU-2020_0204-1
SUSE-SU-2020_1663-1
USN-4225-1
USN-4225-2
USN-4226-1
USN-4227-1
USN-4227-2
USN-4228-1
USN-4228-2

Affected Products

Alt Linux
Linux Kernel
Red Hat
Suse
Ubuntu