CVE-2020-12653: Buffer Overflow
A flaw was found in the way the mwifiexcmdappendvsietlv() in Linux kernel's Marvell WiFi-Ex driver handled vendor specific information elements. A local user could use this flaw to escalate their privileges on the system.
Other sources
An issue was found in Linux kernel before 5.5.4. The mwifiexcmdappendvsietlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.
An issue was found in Linux kernel before 5.5.4. The mwifiexcmdappendvsietlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow.
Reference and upstream commit: https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.4 https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b70261a288ea4d2f4ac7cd04be08a9f0f2de4f4d
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-12653?
CVE-2020-12653 is a vulnerability in the Linux kernel that allows local users to gain privileges or cause a denial of service.
What is the severity of CVE-2020-12653?
CVE-2020-12653 has a severity rating of 7.8 (high).
How does CVE-2020-12653 affect Linux kernel?
CVE-2020-12653 affects the mwifiex_cmd_append_vsie_tlv() function in the Linux kernel's Marvell WiFi-Ex driver, causing a buffer overflow.
How can local users exploit CVE-2020-12653?
Local users can exploit CVE-2020-12653 by triggering a buffer overflow through an incorrect memcpy operation.
Where can I find more information about CVE-2020-12653?
You can find more information about CVE-2020-12653 on the official Git repository and the Debian security tracker.