CVE-2016-8658
published 2016-10-16CVE-2016-8658: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before…
PriorityP424medium6.1CVSS 3.0
AVLACLPRLUINSUCNILAH
EPSS
0.65%
47.5th percentile
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.5-1 (bookworm) | linux 4.7.5-1 (bookworm) |
| linux | linux_kernel | <= 4.7.4 | — |
| linux | linux_kernel | >= 0 < 4.7.5-1 | 4.7.5-1 |
| linux | linux_kernel | >= 0 < 4.7.5-1 | 4.7.5-1 |
| linux | linux_kernel | >= 0 < 4.7.5-1 | 4.7.5-1 |
| linux | linux_kernel | >= 0 < 4.7.5-1 | 4.7.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-103.150 | 3.13.0-103.150 |
| linux | linux_kernel | >= 0 < 4.4.0-51.72 | 4.4.0-51.72 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
nvdv2.05.6MEDIUMAV:L/AC:L/Au:N/C:N/I:P/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker coul
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-11-30·CVSS 4.4
CVE-2016-7097 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the __get_user_asm_ex implementation in the Linux
kernel for x86/x86_64 contained extended asm statements that were
incompatible with the exception table. A local attacker could use this to
gain administrative privileges. (CVE-2016-9644)
Andreas Gruenbacher and Jan Kara discovered that the filesystem
implementation in the Linux kernel did not clear the setgid bit during a
setxattr call. A local attacker could use this to possibly elevate group
privileges. (CVE-2016-7097)
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system cr
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-11-30·CVSS 4.4
CVE-2016-7097 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3146-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the __get_user_asm_ex implementation in the Linux
kernel for x86/x86_64 contained extended asm statements that were
incompatible with the exception table. A local attacker could use this to
gain administrative privileges. (CVE-2016-9644)
Andreas Gruenbacher and Jan Kara discovered that the filesystem
implementation in the Linux kernel did not clear the setgid bit during a
setxattr call. A local attacker could use this to possibly elevate group
priv
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-11-30·CVSS 7.8
CVE-2016-7425 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3145-1 fixed vulnerabilities in the Linux kernel for Ubuntu
14.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for
Ubuntu 12.04 LTS.
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
privileges. (CVE-2016-7425)
Daxing Guo discovered a stack-based buffer overflow in the Broadcom
IEEE802.11n FullMAC driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
privileges. (C
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-11-30·CVSS 7.8
CVE-2016-7425 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
privileges. (CVE-2016-7425)
Daxing Guo discovered a stack-based buffer overflow in the Broadcom
IEEE802.11n FullMAC driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
privileges. (CVE-2016-8658)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version numbe
Red Hat
kernel: Stack buffer overflow in brcmf_cfg80211_start_ap
vendor_redhat·2016-09-07·CVSS 6.1
CVE-2016-8658 [MEDIUM] CWE-121 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap
kernel: Stack buffer overflow in brcmf_cfg80211_start_ap
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
Stack-based buffer overflow in the brcmf_cfg80211_start_ap() function in 'drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c' in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
Statement: This issue does not affect the Linux kernel pac
Debian
CVE-2016-8658: linux - Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/n...
vendor_debian·2016·CVSS 6.1
CVE-2016-8658 [MEDIUM] CVE-2016-8658: linux - Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/n...
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
Scope: local
bookworm: resolved (fixed in 4.7.5-1)
bullseye: resolved (fixed in 4.7.5-1)
forky: resolved (fixed in 4.7.5-1)
sid: resolved (fixed in 4.7.5-1)
trixie: resolved (fixed in 4.7.5-1)
GHSA
GHSA-cq7v-vrjg-jccw: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211
ghsa_unreviewed·2022-05-17
CVE-2016-8658 [MEDIUM] CWE-119 GHSA-cq7v-vrjg-jccw: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
OSV
linux-snapdragon vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Andreas Grue
OSV
linux-raspi2 vulnerabilities
osv·2016-12-20·CVSS 5.5
CVE-2015-8964 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Tilman Schmidt and Sasha Levin discovered a use-after-free condition in the
TTY implementation in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2015-8964)
It was discovered that the Video For Linux Two (v4l2) implementation in the
Linux kernel did not properly handle multiple planes when processing a
VIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2016-4568)
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). (CVE-2016-6213)
Ondrej Kozina di
OSV
linux vulnerabilities
osv·2016-11-30·CVSS 7.8
CVE-2016-7425 [HIGH] linux vulnerabilities
linux vulnerabilities
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
privileges. (CVE-2016-7425)
Daxing Guo discovered a stack-based buffer overflow in the Broadcom
IEEE802.11n FullMAC driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
privileges. (CVE-2016-8658)
OSV
linux vulnerabilities
osv·2016-11-30·CVSS 4.4
CVE-2016-9644 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the __get_user_asm_ex implementation in the Linux
kernel for x86/x86_64 contained extended asm statements that were
incompatible with the exception table. A local attacker could use this to
gain administrative privileges. (CVE-2016-9644)
Andreas Gruenbacher and Jan Kara discovered that the filesystem
implementation in the Linux kernel did not clear the setgid bit during a
setxattr call. A local attacker could use this to possibly elevate group
privileges. (CVE-2016-7097)
Marco Grassi discovered that the driver for Areca RAID Controllers in the
Linux kernel did not properly validate control messages. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
privileges. (CVE-2016-7425)
Daxing Guo discovered a
OSV
linux-lts-xenial vulnerabilities
osv·2016-11-30·CVSS 4.4
[MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3146-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the __get_user_asm_ex implementation in the Linux
kernel for x86/x86_64 contained extended asm statements that were
incompatible with the exception table. A local attacker could use this to
gain administrative privileges. (CVE-2016-9644)
Andreas Gruenbacher and Jan Kara discovered that the filesystem
implementation in the Linux kernel did not clear the setgid bit during a
setxattr call. A local attacker could use this to possibly elevate group
privileges. (CVE-2016-7097)
Marco Grassi discovered that the driver for Areca R
OSV
CVE-2016-8658: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211
osv·2016-10-16·CVSS 6.1
CVE-2016-8658 [MEDIUM] CVE-2016-8658: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
No detection rules found.
No public exploits indexed.
arXiv
Using Sequence-to-Sequence Learning for Repairing C Vulnerabilities
arxiv_fulltext·2019-12-04·CVSS 7.5
[HIGH] Using Sequence-to-Sequence Learning for Repairing C Vulnerabilities
Using Sequence-to-Sequence Learning for Repairing C Vulnerabilities
Zimin Chen
KTH Royal Institue of Technology
[email protected]
Steve Kommrusch
Colorado State University
[email protected]
Martin Monperrus
KTH Royal Institue of Technology
[email protected]
## Abstract
Software vulnerabilities affect all businesses and research is being done to avoid, detect or repair them. In this article, we contribute a new technique for automatic vulnerability fixing. We present a system that uses the rich software development history that can be found on GitHub to train an AI system that generates patches. We apply sequence-to-sequence learning on a big dataset of code changes and we evaluate the trained system on real world vulnerabilities from the CVE database. The result shows the
Bugzilla
CVE-2016-8658 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap
bugzilla·2016-10-13·CVSS 6.1
CVE-2016-8658 [MEDIUM] CVE-2016-8658 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap
CVE-2016-8658 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap
A stack based buffer overflow vulnerability was found in brcmf_cfg80211_start_ap() function. User-space can choose to omit NL80211_ATTR_SSID and only provide raw IE TLV data. When doing so it can provide SSID IE with length exceeding the allowed size. The driver further processes this IE copying it into a local variable without checking the length. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
http://seclists.org/oss-sec/2016/q4/111
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ded89912156b1a47d940a0c954c43afbabd0c42c
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedor
Bugzilla
CVE-2016-8658 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap [fedora-all]
bugzilla·2016-10-13·CVSS 6.1
CVE-2016-8658 [MEDIUM] CVE-2016-8658 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap [fedora-all]
CVE-2016-8658 kernel: Stack buffer overflow in brcmf_cfg80211_start_ap [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ded89912156b1a47d940a0c954c43afbabd0c42chttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.7.5http://www.openwall.com/lists/oss-security/2016/10/13/1http://www.securityfocus.com/bid/93541http://www.ubuntu.com/usn/USN-3145-1http://www.ubuntu.com/usn/USN-3145-2http://www.ubuntu.com/usn/USN-3146-1http://www.ubuntu.com/usn/USN-3146-2https://bugzilla.redhat.com/show_bug.cgi?id=1384403https://github.com/torvalds/linux/commit/ded89912156b1a47d940a0c954c43afbabd0c42chttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ded89912156b1a47d940a0c954c43afbabd0c42chttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.7.5http://www.openwall.com/lists/oss-security/2016/10/13/1http://www.securityfocus.com/bid/93541http://www.ubuntu.com/usn/USN-3145-1http://www.ubuntu.com/usn/USN-3145-2http://www.ubuntu.com/usn/USN-3146-1http://www.ubuntu.com/usn/USN-3146-2https://bugzilla.redhat.com/show_bug.cgi?id=1384403https://github.com/torvalds/linux/commit/ded89912156b1a47d940a0c954c43afbabd0c42c
2016-10-16
Published