CVE-2019-3846: High severity Linux Linux kernel vulnerability
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
Other sources
A flaw was found in Marvell wifi chip driver in Linux kernel. A heap overflow in mwifiexupdatebssdescwithie function in marvell/mwifiex/scan.c allows remote attackers to cause a denial of service(system crash) or possibly execute arbitrary code.
Upstream patch submission:
https://lore.kernel.org/linux-wireless/20190529125220.17066-1-tiwai@suse.de/
— Red Hat
A flaw was found in the Linux kernel's Marvell wifi chip driver. A heap overflow in mwifiexupdatebssdescwithie function in marvell/mwifiex/scan.c allows remote attackers to cause a denial of service(system crash) or execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.4.1.rt56.1027.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.4.1.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.17.1.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.54.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.11.1.rt9.156.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.11.1.el8_0 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Configuration
If wireless networking is not used, blacklist the mwifiex kernel module to prevent misuse of the vulnerable code.
Linux kernel mwifiex module blacklist mwifiex kernel module = enabled - Compensating control
Temporary mitigation: only connect to known-good Wi-Fi networks, or connect via Ethernet instead of Wi-Fi.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-3846?
CVE-2019-3846 has been rated as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2019-3846?
To fix CVE-2019-3846, update your kernel to the recommended versions specified by your distribution, such as Red Hat or Debian.
What systems are affected by CVE-2019-3846?
CVE-2019-3846 affects several Linux kernel versions, particularly those using the mwifiex kernel module.
Is CVE-2019-3846 a remote attack vulnerability?
Yes, CVE-2019-3846 can be exploited remotely when a user connects to a malicious wireless network.
What type of vulnerability is CVE-2019-3846?
CVE-2019-3846 is primarily categorized as a heap overflow vulnerability.