First published: Thu Nov 21 2019(Updated: )
Linux Kernel is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the mwifiex_process_country_ie function in drivers/net/wireless/marvell/mwifiex/sta_ioctl.c. By sending a specially-crafted beacon packet, a remote attacker could overflow a buffer and execute arbitrary code or cause a denial of service on the system.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1062.12.1.rt56.1042.el7 | 0:3.10.0-1062.12.1.rt56.1042.el7 |
redhat/kernel | <0:3.10.0-1062.12.1.el7 | 0:3.10.0-1062.12.1.el7 |
redhat/kernel-alt | <0:4.14.0-115.19.1.el7a | 0:4.14.0-115.19.1.el7a |
redhat/kernel | <0:3.10.0-327.85.1.el7 | 0:3.10.0-327.85.1.el7 |
redhat/kernel | <0:3.10.0-514.73.1.el7 | 0:3.10.0-514.73.1.el7 |
redhat/kernel | <0:3.10.0-693.64.1.el7 | 0:3.10.0-693.64.1.el7 |
redhat/kernel | <0:3.10.0-862.48.1.el7 | 0:3.10.0-862.48.1.el7 |
redhat/kernel | <0:3.10.0-957.46.1.el7 | 0:3.10.0-957.46.1.el7 |
redhat/kernel-rt | <0:4.18.0-147.5.1.rt24.98.el8_1 | 0:4.18.0-147.5.1.rt24.98.el8_1 |
redhat/kernel | <0:4.18.0-147.5.1.el8_1 | 0:4.18.0-147.5.1.el8_1 |
redhat/kernel | <0:4.18.0-80.16.1.el8_0 | 0:4.18.0-80.16.1.el8_0 |
redhat/kernel-rt | <1:3.10.0-693.64.1.rt56.662.el6 | 1:3.10.0-693.64.1.rt56.662.el6 |
Linux Linux kernel | >=3.7<3.16.81 | |
Linux Linux kernel | >=3.17<4.4.210 | |
Linux Linux kernel | >=4.5<4.9.210 | |
Linux Linux kernel | >=4.10<4.14.165 | |
Linux Linux kernel | >=4.15<4.19.96 | |
Linux Linux kernel | >=4.20<5.4.12 | |
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Canonical Ubuntu Linux | =19.10 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
openSUSE Leap | =15.1 | |
IBM Data Risk Manager | <=2.0.6 | |
ubuntu/linux | <4.15.0-74.84 | 4.15.0-74.84 |
ubuntu/linux | <5.0.0-38.41 | 5.0.0-38.41 |
ubuntu/linux | <5.3.0-26.28 | 5.3.0-26.28 |
ubuntu/linux | <4.4.0-171.200 | 4.4.0-171.200 |
ubuntu/linux-aws | <4.15.0-1057.59 | 4.15.0-1057.59 |
ubuntu/linux-aws | <5.0.0-1023.26 | 5.0.0-1023.26 |
ubuntu/linux-aws | <5.3.0-1009.10 | 5.3.0-1009.10 |
ubuntu/linux-aws | <4.4.0-1060.64 | 4.4.0-1060.64 |
ubuntu/linux-aws | <4.4.0-1100.111 | 4.4.0-1100.111 |
ubuntu/linux-aws-5.0 | <5.0.0-1023.26~18.04.1 | 5.0.0-1023.26~18.04.1 |
ubuntu/linux-aws-hwe | <4.15.0-1057.59~16.04.1 | 4.15.0-1057.59~16.04.1 |
ubuntu/linux-azure | <5.0.0-1028.30~18.04.1 | 5.0.0-1028.30~18.04.1 |
ubuntu/linux-azure | <5.0.0-1028.30 | 5.0.0-1028.30 |
ubuntu/linux-azure | <5.3.0-1009.10 | 5.3.0-1009.10 |
ubuntu/linux-azure | <4.15.0-1066.71~14.04.1 | 4.15.0-1066.71~14.04.1 |
ubuntu/linux-azure | <4.15.0-1066.71 | 4.15.0-1066.71 |
ubuntu/linux-azure-5.3 | <5.3.0-1009.10~18.04.1 | 5.3.0-1009.10~18.04.1 |
ubuntu/linux-gcp | <5.0.0-1028.29~18.04.1 | 5.0.0-1028.29~18.04.1 |
ubuntu/linux-gcp | <5.0.0-1028.29 | 5.0.0-1028.29 |
ubuntu/linux-gcp | <5.3.0-1011.12 | 5.3.0-1011.12 |
ubuntu/linux-gcp | <4.15.0-1052.56 | 4.15.0-1052.56 |
ubuntu/linux-gcp-5.3 | <5.3.0-1010.11~18.04.1 | 5.3.0-1010.11~18.04.1 |
ubuntu/linux-gke-4.15 | <4.15.0-1050.53 | 4.15.0-1050.53 |
ubuntu/linux-gke-5.0 | <5.0.0-1027.28~18.04.1 | 5.0.0-1027.28~18.04.1 |
ubuntu/linux-hwe | <5.3.0-26.28~18.04.1 | 5.3.0-26.28~18.04.1 |
ubuntu/linux-hwe | <4.15.0-74.83~16.04.1 | 4.15.0-74.83~16.04.1 |
ubuntu/linux-kvm | <4.15.0-1052.52 | 4.15.0-1052.52 |
ubuntu/linux-kvm | <5.0.0-1024.26 | 5.0.0-1024.26 |
ubuntu/linux-kvm | <5.3.0-1009.10 | 5.3.0-1009.10 |
ubuntu/linux-kvm | <4.4.0-1064.71 | 4.4.0-1064.71 |
ubuntu/linux-lts-xenial | <4.4.0-171.200~14.04.1 | 4.4.0-171.200~14.04.1 |
ubuntu/linux-oem | <4.15.0-1066.76 | 4.15.0-1066.76 |
ubuntu/linux-oem | <4.15.0-1066.76 | 4.15.0-1066.76 |
ubuntu/linux-oem-osp1 | <5.0.0-1033.38 | 5.0.0-1033.38 |
ubuntu/linux-oem-osp1 | <5.0.0-1033.38 | 5.0.0-1033.38 |
ubuntu/linux-oracle | <4.15.0-1031.34 | 4.15.0-1031.34 |
ubuntu/linux-oracle | <5.0.0-1009.14 | 5.0.0-1009.14 |
ubuntu/linux-oracle | <5.3.0-1008.9 | 5.3.0-1008.9 |
ubuntu/linux-oracle | <4.15.0-1031.34~16.04.1 | 4.15.0-1031.34~16.04.1 |
ubuntu/linux-oracle-5.0 | <5.0.0-1009.14~18.04.1 | 5.0.0-1009.14~18.04.1 |
ubuntu/linux-raspi2 | <4.15.0-1053.57 | 4.15.0-1053.57 |
ubuntu/linux-raspi2 | <5.0.0-1024.25 | 5.0.0-1024.25 |
ubuntu/linux-raspi2 | <5.3.0-1015.17 | 5.3.0-1015.17 |
ubuntu/linux-raspi2 | <4.4.0-1127.136 | 4.4.0-1127.136 |
ubuntu/linux-snapdragon | <4.15.0-1070.77 | 4.15.0-1070.77 |
ubuntu/linux-snapdragon | <4.4.0-1131.139 | 4.4.0-1131.139 |
debian/linux | 4.19.249-2 4.19.304-1 5.10.209-2 5.10.216-1 6.1.76-1 6.1.90-1 6.7.12-1 6.8.9-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)