|
Message-ID: <20191125141615.GA10910@openwall.com> Date: Mon, 25 Nov 2019 15:16:15 +0100 From: Solar Designer <solar@...nwall.com> To: qize wang <wangqize888888888@...il.com> Cc: oss-security@...ts.openwall.com Subject: Re: Linux kernel: heap overflow in the marvell wifi driver On Fri, Nov 22, 2019 at 08:51:31PM +0800, qize wang wrote: > some flaws were found in the Linux kernel's Marvell wifi chip driver. > multi heap overflow in mwifiex_process_tdls_action_frame function in > marvell/mwifiex/tdls.c which allows remote attackers to cause a denial > of service(system crash) or execute arbitrary code. > > the station receive a tdls setup request or respone frame which IE 's > length is larger than the heap buffer assigned (for example : the > EID_SUPP_RATES IE's length > 255) will cause heap overflow?? Red Hat has assigned CVE-2019-14901 to this issue. Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.