cbcvebase.
CVE-2020-12654
published 2020-05-05

CVE-2020-12654: An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a…

PriorityP433high7.1CVSS 3.1
AVAACHPRNUIRSUCHIHAH
EPSS
1.22%
65.6th percentile
An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.5.13-1 (bookworm)linux 5.5.13-1 (bookworm)
linuxlinux_kernel< 5.5.45.5.4
linuxlinux_kernel>= 0 < 5.5.13-15.5.13-1
linuxlinux_kernel>= 0 < 5.5.13-15.5.13-1
linuxlinux_kernel>= 0 < 5.5.13-15.5.13-1
linuxlinux_kernel>= 0 < 5.5.13-15.5.13-1
linuxlinux_kernel>= 0 < 3.13.0-180.2313.13.0-180.231
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-11_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:A/AC:H/Au:N/C:P/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.