CVE-2019-14896: Buffer Overflow
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbsibssjoinexisting function is called after a STA connects to an AP.
Other sources
A heap-based buffer overflow vulnerability was found in the Linux kernel's Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbsibssjoinexisting function is called after a STA connects to an AP.
A vulnerability was found in marvell wifi chip driver in Linux kernel. There is a heap-based buffer overflow in lbsibssjoinexisting function in drivers/net/wireless/marvell/libertas/cfg.c allows remote attackers to cause a denial of service(system crash) or possibly execute arbitrary code. When STA connects to AP, addierates function will be called for STA.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-754.33.1.el6 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14896?
CVE-2019-14896 is a critical vulnerability that can lead to a denial of service and potentially allow for arbitrary code execution.
How do I fix CVE-2019-14896?
To fix CVE-2019-14896, upgrade your Linux kernel to a version higher than 5.10.226-1 or apply relevant patches provided by your distribution.
Which versions of the Linux kernel are affected by CVE-2019-14896?
CVE-2019-14896 affects Linux kernel versions from 2.6.32 up to and including 5.4.16.
What types of systems are vulnerable to CVE-2019-14896?
Systems running the affected versions of the Linux kernel, including various distributions such as Red Hat, Ubuntu, and Debian, are vulnerable to CVE-2019-14896.
Can CVE-2019-14896 be exploited remotely?
Yes, CVE-2019-14896 can be exploited remotely by an attacker to cause a system crash or execute arbitrary code when handling connections.