PT-2019-5253 · Broadcom+5 · Brcmfmac Wifi Driver+5

Hugues Anguelkov

·

Published

2019-02-19

·

Updated

2024-06-15

·

CVE-2019-9500

CVSS v3.1

8.3

High

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Broadcom brcmfmac WiFi driver versions prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
Description The issue is related to a heap buffer overflow in the brcmf wowl nd results function. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can trigger this overflow. This can be exploited to compromise the host or, in combination with other vulnerabilities, can be used remotely. In the worst-case scenario, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system by sending specially-crafted WiFi packets. More typically, this issue will result in denial-of-service conditions.
Recommendations For versions prior to commit 1b5e2423164b3670e8bc9170e8bc9174e4762d297990deff, consider disabling the Wake-up on Wireless LAN functionality to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1893
ALT-PU-2019-1896
ALT-PU-2019-2050
ALT-PU-2019-2063
ALT-PU-2019-2076
ALT-PU-2019-2077
BDU:2020-02044
CESA-2019_2600
CESA-2019_2703
CESA-2019_2741
CVE-2019-9500
DLA-1824-1
DSA-4465-1
OPENSUSE-SU-2019:1404-1
OPENSUSE-SU-2019:1479-1
OPENSUSE-SU-2019_1404-1
OPENSUSE-SU-2019_1479-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2019:2600
RHSA-2019:2609
RHSA-2019:2703
RHSA-2019:2741
RHSA-2019:2945
RHSA-2019:3217
RHSA-2019:4168
RHSA-2019:4171
RHSA-2019_2600
RHSA-2019_2609
RHSA-2019_2703
RHSA-2019_2741
SUSE-SU-2019:1240-1
SUSE-SU-2019:1241-1
SUSE-SU-2019:1242-1
SUSE-SU-2019:1244-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:2430-1
USN-3979-1
USN-3980-1
USN-3980-2
USN-3981-1
USN-3981-2

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Brcmfmac Wifi Driver