CVE-2019-9503

NameCVE-2019-9503
DescriptionThe Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver receives the firmware event frame from the host, the appropriate handler is called. This frame validation can be bypassed if the bus used is USB (for instance by a wifi dongle). This can allow firmware event frames from a remote source to be processed. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1799-1, DLA-1824-1, DSA-4465-1
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)jessie3.16.56-1+deb8u1vulnerable
jessie (security)3.16.81-1fixed
stretch4.9.210-1fixed
stretch (security)4.9.189-3+deb9u2fixed
buster4.19.98-1fixed
buster (security)4.19.67-2+deb10u2fixed
bullseye5.4.19-1fixed
sid5.5.13-2fixed
linux-4.9 (PTS)jessie (security)4.9.210-1~deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)4.19.37-4
linuxsourcejessie3.16.68-1DLA-1799-1
linuxsourcestretch4.9.168-1+deb9u3DSA-4465-1
linux-4.9sourcejessie4.9.168-1+deb9u3~deb8u1DLA-1824-1

Notes

https://git.kernel.org/linus/a4176ec356c73a46c07c181c6d04039fafa34a9f (5.1-rc1)

Search for package or bug name: Reporting problems