kernel: Heap overflow in mwifiex_update_bss_desc_with_ie function in marvell/mwifiex/scan.c
Published Jun 3, 2019
8.8
HIGHCVSS 3.1
EPSS 5.65%
Description
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
Affected products
- Vendor n/a Product Kernel Defaultunknown
Affected
- n/a
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Kernel | unknown | Affected
|
Configuration 1
- ≥ 3.0 · < 3.16.70
- ≥ 3.17 · < 4.4.186
- ≥ 4.5 · < 4.9.186
- ≥ 4.10 · < 4.14.134
- ≥ 4.15 · < 4.19.59
- ≥ 4.20 · < 5.1.18
Configuration 2
- 6.0
- 7.0
- 8.0
Configuration 3
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- ≥ 9.5
- n/a
- n/a
Configuration 8
- 29
- 30
Configuration 9
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.4.1.el7
Fixed · RHSA-2019:3055
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.17.1.el7a
Fixed · RHSA-2020:0174
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.4.1.rt56.1027.el7
Fixed · RHSA-2019:3089
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2019:3076
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.54.1.el7
Fixed · RHSA-2020:2289
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.11.1.el8_0
Fixed · RHSA-2019:2703
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.11.1.rt9.156.el8_0
Fixed · RHSA-2019:2741
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.54.1.el7
Fixed · RHSA-2020:2289
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.4.1.el7 | Fixed | RHSA-2019:3055 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.17.1.el7a | Fixed | RHSA-2020:0174 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.4.1.rt56.1027.el7 | Fixed | RHSA-2019:3089 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2019:3076 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.54.1.el7 | Fixed | RHSA-2020:2289 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.11.1.el8_0 | Fixed | RHSA-2019:2703 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.11.1.rt9.156.el8_0 | Fixed | RHSA-2019:2741 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.54.1.el7 | Fixed | RHSA-2020:2289 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is currently rated as Important as it is possible for an attacker to setup a wifi access point with identical configuration in another location and intercept have the system auto connect and possibly be exploited.
Red Hat mitigation
This flaw requires a system with marvell wifi network card to be attempting to connect to a attacker controlled wifi network. A temporary mitigation may be to only connect to known-good networks via wifi, or connect to a network via ethernet. Alternatively if wireless networking is not used the mwifiex kernel module can be blacklisted to prevent misuse of the vulnerable code.
References (33)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2703 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2741 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3055 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3076 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3089 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0174 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3846 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1713059 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3846 x_refsource_CONFIRMIssue TrackingMitigationPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-13466 Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00010.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-3846
- https://seclists.org/bugtraq/2019/Jul/33 mailing-listx_refsource_BUGTRAQMailing ListPatchThird Party Advisory
- https://seclists.org/bugtraq/2019/Jun/26 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/oss-sec/2019/q2/133 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190710-0002/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4093-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4094-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4095-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4095-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4117-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4118-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3846
- https://www.debian.org/security/2019/dsa-4465 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data