| Name | CVE-2019-14897 |
| Description | A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA. |
| Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-2068-1, DLA-2114-1 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| linux (PTS) | bullseye | 5.10.218-1 | fixed |
| bullseye (security) | 5.10.221-1 | fixed | |
| bookworm | 6.1.94-1 | fixed | |
| bookworm (security) | 6.1.99-1 | fixed | |
| trixie | 6.9.10-1 | fixed | |
| sid | 6.9.12-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| linux | source | jessie | 3.16.81-1 | DLA-2068-1 | ||
| linux | source | stretch | 4.9.210-1 | |||
| linux | source | buster | 4.19.98-1 | |||
| linux | source | (unstable) | 5.4.19-1 | |||
| linux-4.9 | source | jessie | 4.9.210-1~deb8u1 | DLA-2114-1 |
https://www.openwall.com/lists/oss-security/2019/11/22/1