kernel: heap-overflow in mwifiex_set_wmm_params() function of Marvell WiFi driver leading to DoS
Published Nov 25, 2019
7.8
HIGHCVSS 3.1
EPSS 0.49%
Description
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
Affected products
Configuration 1
- ≥ 4.10 · < 4.14.146
- ≥ 4.15 · < 4.19.75
- ≥ 4.20 · < 5.2.17
Configuration 2
- 8.1
- 8.2
- 8.4
- 8.6
- 8.1
- 8.2
- 8.4
- 8.6
- 5
- 6.0
- 7.0
- 8.0
- 7_s390x
- 8.1
- 8.2
- 8.4
- 8.6
- 8
- 8
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
Configuration 3
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.el7
Fixed · RHSA-2020:1016
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.17.1.el7a
Fixed · RHSA-2020:0174
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1127.rt56.1093.el7
Fixed · RHSA-2020:1070
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.5.1.el8_1
Fixed · RHSA-2020:0339
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.5.1.rt24.98.el8_1
Fixed · RHSA-2020:0328
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.el7 | Fixed | RHSA-2020:1016 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.17.1.el7a | Fixed | RHSA-2020:0174 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1127.rt56.1093.el7 | Fixed | RHSA-2020:1070 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.5.1.el8_1 | Fixed | RHSA-2020:0339 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.5.1.rt24.98.el8_1 | Fixed | RHSA-2020:0328 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/errata/RHSA-2020:0174 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0328 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0339 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14815 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2019-14815 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1744137 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14815 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/torvalds/linux/commit/7caac62ed598a196d6ddf8d9c121e12e082cac3a x_refsource_MISCIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lore.kernel.org/linux-wireless/20190828020751.13625-1-huangwenabc%40gmail.com x_refsource_MISCIssue TrackingMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14815
- https://security.netapp.com/advisory/ntap-20200103-0001/ x_refsource_CONFIRMMailing ListPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14815
- https://www.openwall.com/lists/oss-security/2019/08/28/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
Change history (0)
No recorded changes yet.