Back

MEDIUM

kernel: b43: format string leaking into error msgs

Published Jun 7, 2013

Description

Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.

Affected products

Remediation

Red Hat statement

This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5. This issue does affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG. Future updates for Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG may address this issue.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Jun 7, 2013
Updated Aug 6, 2024
Reserved Apr 11, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jun 6, 2013