Описание
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
A vulnerability was found in the Linux kernel’s Intel wireless driver (drivers/net/wireless/iwlwifi/iwl-agn-sta.c) where the driver could be forced to connect to an invalid station. An attacker could use this flaw to corrupt memory or create a situation allowing for privilege escalation.
Отчет
The patch committed by upstream will prevent the misuse of the invalid station id, however it does not prevent the incorrect state being entered. Red Hat Enterprise Linux 6,7 and 8 are not affected by this flaw. Red Hat Enterprise Linux 5 does not have the "fix" applied and may be vulnerable to this flaw. Red Hat does not have plans to fix EL5 at this stage in its lifecycle. This flaw only applies to systems running and using the intel iwlwifi driver.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | ||
| Red Hat Enterprise Linux 6 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | ||
| Red Hat Enterprise Linux 8 | kernel | Not affected | ||
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | ||
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/ne ...
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
EPSS
6.2 Medium
CVSS3