Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 25 Nov 2019 15:16:15 +0100
From: Solar Designer <solar@...nwall.com>
To: qize wang <wangqize888888888@...il.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Linux kernel: heap overflow in the marvell wifi driver

On Fri, Nov 22, 2019 at 08:51:31PM +0800, qize wang wrote:
> some flaws were found in the Linux kernel's Marvell wifi chip driver. 
> multi heap overflow in mwifiex_process_tdls_action_frame function in 
> marvell/mwifiex/tdls.c which allows remote attackers to cause a denial 
> of service(system crash) or execute arbitrary code.
> 
> the station receive a tdls setup request or respone frame which IE 's 
> length is larger than the heap buffer assigned (for example : the 
> EID_SUPP_RATES IE's length > 255) will cause heap overflow??

Red Hat has assigned CVE-2019-14901 to this issue.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.