CVE-2019-9503 — Improper Input Validation in Brcmfmac Wifi Driver
Severity
8.3HIGHNVD
NVD3.1OSV8.1OSV5.6
EPSS
0.5%
top 33.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16
Latest updateOct 1
Description
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver receives the firmware event frame from the host, the appropriate handler is called. This frame validation can be bypassed if the bus used is USB (for instance by a wifi dongle). This can …
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0
Affected Packages8 packages
▶CVEListV5broadcom/brcmfmac_wifi_drivercommit prior to 1b5e2423164b3670e8bc9174e4762d297990deff, commit prior to a4176ec356c73a46c07c181c6d04039fafa34a9f+1
Also affects: Enterprise Linux 6.0, 7.0
Patches
🔴Vulnerability Details
9GHSA▶
GHSA-6g85-84jx-q393: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass↗2022-05-24
GHSA▶
GHSA-6jhq-h73f-x439: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow↗2022-05-24
OSV▶
CVE-2019-9500: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow↗2020-01-16
OSV▶
CVE-2019-9503: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass↗2020-01-16
📋Vendor Advisories
12Red Hat▶
linux-firmware: Transmission of data encrypted with an all-zero session key after disassociation↗2020-02-05
📄Research Papers
1💬Community
4Bugzilla▶
CVE-2019-15126 linux-firmware: Transmission of data encrypted with an all-zero session key after disassociation↗2020-02-27