kernel: heap overflow in mwifiex_set_uap_rates() function of Marvell Wifi Driver leading to DoS
Published Sep 20, 2019
7.8
HIGHCVSS 3.1
EPSS 0.87%
Description
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
Affected products
-
- Version all versions up to, excluding 5.3StatusaffectedConstraints-
- Version
Configuration 1
- ≥ 3.7 · < 3.16.74
- ≥ 3.17 · < 4.4.194
- ≥ 4.5 · < 4.9.194
- ≥ 4.10 · < 4.14.146
- ≥ 4.15 · < 4.19.75
- ≥ 4.20 · < 5.2.17
Configuration 2
- 5.0
- 6.0
- 7.0
- 8.0
- 8.1
- 8.2
- 8.4
- 8
- 8
- 8.2
- 8.4
- 8.2
- 8.4
- 8.2
- 8.4
- 8.2
- 8.4
- 2.0
Configuration 3
- 8.0
Configuration 4
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 6
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- n/a
Configuration 20
- n/a
Configuration 21
- n/a
Configuration 22
- n/a
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.el7
Fixed · RHSA-2020:1016
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.17.1.el7a
Fixed · RHSA-2020:0174
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.5.1.el8_1
Fixed · RHSA-2020:0339
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.5.1.rt24.98.el8_1
Fixed · RHSA-2020:0328
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise MRG 2
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.el7 | Fixed | RHSA-2020:1016 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.17.1.el7a | Fixed | RHSA-2020:0174 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.5.1.el8_1 | Fixed | RHSA-2020:0339 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.5.1.rt24.98.el8_1 | Fixed | RHSA-2020:0328 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (29)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/08/28/1 mailing-listx_refsource_MLISTExploitMailing ListPatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0174 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0328 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0339 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14814 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2019-14814 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1744130 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14814 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7caac62ed598a196d6ddf8d9c121e12e082cac3a
- https://github.com/torvalds/linux/commit/7caac62ed598a196d6ddf8d9c121e12e082cac3a x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/ vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/ vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14814
- https://seclists.org/bugtraq/2019/Nov/11 mailing-listx_refsource_BUGTRAQMailing ListPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4157-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4157-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4162-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4162-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4163-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4163-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14814
- https://www.openwall.com/lists/oss-security/2019/08/28/1 x_refsource_MISCExploitMailing ListPatchThird Party Advisory
Change history (4)
- MITRE
- CVSS vector changed from CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H to
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H → CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- CVSS score changed from 6.7 to
5.5 6.7 → 5.5
- CVSS vector changed from CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H to
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- REDHAT
- CVSS vector changed from CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H to
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H → CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CVSS score changed from 5.5 to
6.7 5.5 → 6.7
- CVSS vector changed from CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H to
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H