CVE-2019-14815Heap-based Buffer Overflow in Kernel

Severity
7.8HIGHNVD
EPSS
0.2%
top 59.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateApr 20

Description

A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel4.104.14.146+2
Debianlinux/linux_kernel< 5.2.17-1+3
CVEListV5linux/kerneln/a

Also affects: Enterprise Linux 5, 6.0, 7.0, 8.0, 7, 8.1, 8.2, 8.4, 8.6, 8

Patches

🔴Vulnerability Details

6
Kernel
fortify: Detect struct member overflows in memcpy() at compile-time2021-04-20
CVEList
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver2019-11-25
OSV
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver2019-11-25
OSV
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities2019-10-22
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2019-10-22

📋Vendor Advisories

6
Ubuntu
Linux kernel (Azure) vulnerabilities2019-10-23
Ubuntu
Linux kernel (HWE) vulnerabilities2019-10-22
Ubuntu
Linux kernel vulnerabilities2019-10-22
Ubuntu
Linux kernel vulnerabilities2019-10-17
Red Hat
kernel: heap-overflow in mwifiex_set_wmm_params() function of Marvell WiFi driver leading to DoS2019-08-28

💬Community

3
Bugzilla
CVE-2019-14815 kernel: heap-overflow in mwifiex_set_wmm_params() function of Marvell Wifi Driver leading to DoS [fedora-all]2019-11-25
Bugzilla
CVE-2019-14815 kernel: heap-overflow in mwifiex_set_wmm_params() function of Marvell Wifi Driver leading to DoS [fedora-all]2019-08-28
Bugzilla
CVE-2019-14815 kernel: heap-overflow in mwifiex_set_wmm_params() function of Marvell WiFi driver leading to DoS2019-08-21