CVE-2019-3846: High severity Linux Linux kernel vulnerability
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
Other sources
A flaw was found in Marvell wifi chip driver in Linux kernel. A heap overflow in mwifiexupdatebssdescwithie function in marvell/mwifiex/scan.c allows remote attackers to cause a denial of service(system crash) or possibly execute arbitrary code.
Upstream patch submission:
https://lore.kernel.org/linux-wireless/20190529125220.17066-1-tiwai@suse.de/
— Red Hat
A flaw was found in the Linux kernel's Marvell wifi chip driver. A heap overflow in mwifiexupdatebssdescwithie function in marvell/mwifiex/scan.c allows remote attackers to cause a denial of service(system crash) or execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.4.1.rt56.1027.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.4.1.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.17.1.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.54.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.11.1.rt9.156.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.11.1.el8_0 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.2.6-1Fixed in 7.2.8-1 - Configuration
If wireless networking is not used, blacklist the mwifiex kernel module to prevent use of the vulnerable code.
Linux kernel mwifiex module module blacklist = blacklisted - Compensating control
Only connect via Wi-Fi to known-good networks, or use an Ethernet connection instead of wireless networking.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-3846?
CVE-2019-3846 has been rated as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2019-3846?
To fix CVE-2019-3846, update your kernel to the recommended versions specified by your distribution, such as Red Hat or Debian.
What systems are affected by CVE-2019-3846?
CVE-2019-3846 affects several Linux kernel versions, particularly those using the mwifiex kernel module.
Is CVE-2019-3846 a remote attack vulnerability?
Yes, CVE-2019-3846 can be exploited remotely when a user connects to a malicious wireless network.
What type of vulnerability is CVE-2019-3846?
CVE-2019-3846 is primarily categorized as a heap overflow vulnerability.