CVE-2020-12654Out-of-bounds Write in Kernel

Severity
7.1HIGHNVD
OSV5.5
EPSS
0.4%
top 39.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 5
Latest updateApr 12

Description

An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel< 5.5.4
Debianlinux/linux_kernel< 5.5.13-1+3
Ubuntulinux/linux_kernel< 3.13.0-180.231
debiandebian/linux< linux 5.5.13-1 (bookworm)

Patches

🔴Vulnerability Details

4
GHSA
GHSA-r2mg-x3w3-w45q: An issue was found in Linux kernel before 52022-05-24
Kernel
fortify: Detect struct member overflows in memcpy() at compile-time2021-04-20
OSV
linux, linux-lts-trusty vulnerabilities2020-06-10
OSV
CVE-2020-12654: An issue was found in Linux kernel before 52020-05-05

📋Vendor Advisories

5
Ubuntu
Linux kernel vulnerabilities2020-06-10
Ubuntu
Linux kernel vulnerabilities2020-06-10
Microsoft
An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an inc2020-05-12
Red Hat
kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c2020-01-27
Debian
CVE-2020-12654: linux - An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in...2020

📄Research Papers

1
arXiv
Securing Monolithic Kernels using Compartmentalization2024-04-12

💬Community

2
Bugzilla
CVE-2020-12654 kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c2020-05-06
Bugzilla
CVE-2020-12654 kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c [fedora-all]2020-05-06