CVE-2023-52525
published 2024-03-02CVE-2023-52525: In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path…
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
Only skip the code path trying to access the rfc1042 headers when the
buffer is too small, so the driver can still process packets without
rfc1042 headers.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 11958528161731c58e105b501ed60b83a91ea941 < aef7a0300047e7b4707ea0411dc9597cba108fc8 | aef7a0300047e7b4707ea0411dc9597cba108fc8 |
| linux | linux | >= 29eca8b7863d1d7de6c5b746b374e3487d14f154 < b8e260654a29de872e7cb85387d8ab8974694e8e | b8e260654a29de872e7cb85387d8ab8974694e8e |
| linux | linux | >= 3975e21d4d01efaf0296ded40d11c06589c49245 < 6b706286473db4fd54b5f869faa67f4a8cb18e99 | 6b706286473db4fd54b5f869faa67f4a8cb18e99 |
| linux | linux | >= 3fe3923d092e22d87d1ed03e2729db444b8c1331 < 10a18c8bac7f60d32b7af22da03b66f350beee38 | 10a18c8bac7f60d32b7af22da03b66f350beee38 |
| linux | linux | >= 4.14.326 < 4.14.327 | 4.14.327 |
| linux | linux | >= 4.19.295 < 4.19.296 | 4.19.296 |
| linux | linux | >= 5.10.195 < 5.10.198 | 5.10.198 |
| linux | linux | >= 5.15.132 < 5.15.135 | 5.15.135 |
| linux | linux | >= 5.4.257 < 5.4.258 | 5.4.258 |
| linux | linux | >= 6.1.53 < 6.1.57 | 6.1.57 |
| linux | linux | >= 6.4.16 < 6.5 | 6.5 |
| linux | linux | >= 6.5.3 < 6.5.7 | 6.5.7 |
| linux | linux | >= 650d1bc02fba7b42f476d8b6643324abac5921ed < be2ff39b1504c5359f4a083c1cfcad21d666e216 | be2ff39b1504c5359f4a083c1cfcad21d666e216 |
| linux | linux | >= 7c54b6fc39eb1aac51cf2945f8a25e2a47fdca02 < 5afb996349cb6d1f14d6ba9aaa7aed3bd82534f6 | 5afb996349cb6d1f14d6ba9aaa7aed3bd82534f6 |
| linux | linux | >= 8824aa4ab62c800f75d96f48e1883a5f56ec5869 < 16cc18b9080892d1a0200a38e36ae52e464bc555 | 16cc18b9080892d1a0200a38e36ae52e464bc555 |
| linux | linux | >= f517c97fc129995de77dd06aa5a74f909ebf568f < 71b1d2b57f145c8469aa9346f0fd57bf59b2b89c | 71b1d2b57f145c8469aa9346f0fd57bf59b2b89c |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.8-1 | 6.5.8-1 |
| linux | linux_kernel | >= 0 < 6.5.8-1 | 6.5.8-1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
vendor_redhat·2024-03-02·CVSS 7.1
CVE-2023-52525 [HIGH] CWE-125 kernel: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
kernel: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
Only skip the code path trying to access the rfc1042 headers when the
buffer is too small, so the driver can still process packets without
rfc1042 headers.
An out-of-bounds vulnerability was found in the mwifiex_process_rx_packet() function in the Linux kernel, which occurs from improper boundary checks when accessing the RFC1042 headers in received packets. If the packet buffer is too small, the function skips code paths that handle these headers, which could lead to incorrect packet processing and a potential out-of-bounds access, causing a crash or memory corruption.
Statemen
Debian
CVE-2023-52525: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mwifi...
vendor_debian·2023·CVSS 7.1
CVE-2023-52525 [HIGH] CVE-2023-52525: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mwifi...
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.205-1)
forky: resolved (fixed in 6.5.8-1)
sid: resolved (fixed in 6.5.8-1)
trixie: resolved (fixed in 6.5.8-1)
GHSA
GHSA-xqf9-qrgq-fxfv: In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
Only skip th
ghsa_unreviewed·2024-03-03
CVE-2023-52525 [HIGH] CWE-125 GHSA-xqf9-qrgq-fxfv: In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
Only skip th
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
Only skip the code path trying to access the rfc1042 headers when the
buffer is too small, so the driver can still process packets without
rfc1042 headers.
OSV
CVE-2023-52525: In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the
osv·2024-03-02·CVSS 7.1
CVE-2023-52525 [HIGH] CVE-2023-52525: In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/10a18c8bac7f60d32b7af22da03b66f350beee38https://git.kernel.org/stable/c/16cc18b9080892d1a0200a38e36ae52e464bc555https://git.kernel.org/stable/c/5afb996349cb6d1f14d6ba9aaa7aed3bd82534f6https://git.kernel.org/stable/c/6b706286473db4fd54b5f869faa67f4a8cb18e99https://git.kernel.org/stable/c/71b1d2b57f145c8469aa9346f0fd57bf59b2b89chttps://git.kernel.org/stable/c/aef7a0300047e7b4707ea0411dc9597cba108fc8https://git.kernel.org/stable/c/b8e260654a29de872e7cb85387d8ab8974694e8ehttps://git.kernel.org/stable/c/be2ff39b1504c5359f4a083c1cfcad21d666e216https://git.kernel.org/stable/c/10a18c8bac7f60d32b7af22da03b66f350beee38https://git.kernel.org/stable/c/16cc18b9080892d1a0200a38e36ae52e464bc555https://git.kernel.org/stable/c/5afb996349cb6d1f14d6ba9aaa7aed3bd82534f6https://git.kernel.org/stable/c/6b706286473db4fd54b5f869faa67f4a8cb18e99https://git.kernel.org/stable/c/71b1d2b57f145c8469aa9346f0fd57bf59b2b89chttps://git.kernel.org/stable/c/aef7a0300047e7b4707ea0411dc9597cba108fc8https://git.kernel.org/stable/c/b8e260654a29de872e7cb85387d8ab8974694e8ehttps://git.kernel.org/stable/c/be2ff39b1504c5359f4a083c1cfcad21d666e216
2024-03-02
Published