Back

MEDIUM

wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()

Published Oct 21, 2024

Description

Replace one-element array with a flexible-array member in `struct host_cmd_ds_802_11_scan_ext`.

With this, fix the following warning:

elo 16 17:51:58 surfacebook kernel: ------------[ cut here ]------------ elo 16 17:51:58 surfacebook kernel: memcpy: detected field-spanning write (size 243) of single field "ext_scan->tlv_buffer" at drivers/net/wireless/marvell/mwifiex/scan.c:2239 (size 1) elo 16 17:51:58 surfacebook kernel: WARNING: CPU: 0 PID: 498 at drivers/net/wireless/marvell/mwifiex/scan.c:2239 mwifiex_cmd_802_11_scan_ext+0x83/0x90 [mwifiex]

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, prevent the `mwifiex` kernel module from loading. This can be achieved by creating a blacklist entry for the module. 1. Create a new file `/etc/modprobe.d/blacklist-mwifiex.conf` with the following content: ``` blacklist mwifiex install mwifiex /bin/true ``` 2. Regenerate the initramfs to ensure the blacklist is applied during boot: ```bash sudo dracut -f -v ``` or for systems using `mkinitrd`: ```bash sudo mkinitrd -f /boot/initramfs-$(uname -r).img $(uname -r) ``` 3. Reboot the system for the changes to take effect. This mitigation will disable functionality provided by the `mwifiex` Wi-Fi driver, which may impact wireless network connectivity if your system relies on this specific hardware.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated May 12, 2026
Reserved Oct 21, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024