PT-2019-5253 · Broadcom+5 · Brcmfmac Wifi Driver+5
Hugues Anguelkov
·
Published
2019-02-19
·
Updated
2024-06-15
·
CVE-2019-9500
CVSS v3.1
8.3
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Broadcom brcmfmac WiFi driver versions prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
Description
The issue is related to a heap buffer overflow in the
brcmf wowl nd results function. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can trigger this overflow. This can be exploited to compromise the host or, in combination with other vulnerabilities, can be used remotely. In the worst-case scenario, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system by sending specially-crafted WiFi packets. More typically, this issue will result in denial-of-service conditions.Recommendations
For versions prior to commit 1b5e2423164b3670e8bc9170e8bc9174e4762d297990deff, consider disabling the Wake-up on Wireless LAN functionality to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Brcmfmac Wifi Driver