The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

Project Subscriptions

Vendors Products
Broadcom Subscribe
Brcmfmac Driver Subscribe
Linux Kernel Subscribe
Enterprise Linux Subscribe
Rhel Eus Subscribe
Rhel Extras Rt Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1824-1 linux-4.9 security update
Debian DSA Debian DSA DSA-4465-1 linux security update
EUVD EUVD EUVD-2019-18874 The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
Ubuntu USN Ubuntu USN USN-3979-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3980-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3980-2 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3981-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3981-2 Linux kernel (HWE) vulnerabilities
Fixes

Solution

https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-04T21:54:44.139Z

Reserved: 2019-03-01T00:00:00.000Z

Link: CVE-2019-9500

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-16T21:15:12.007

Modified: 2024-11-21T04:51:44.480

Link: CVE-2019-9500

cve-icon Redhat

Severity : Important

Publid Date: 2019-02-19T00:00:00Z

Links: CVE-2019-9500 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses