UBUNTU-CVE-2023-1380
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-1380
UBUNTU-CVE-2023-1380
Summary:
Details: A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
References: https://ubuntu.com/security/CVE-2023-1380, https://www.openwall.com/lists/oss-security/2023/03/13/1, https://lore.kernel.org/linux-wireless/[email protected]/T/#u, https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next.git/commit/?h=for-next&id=0da40e018fd034d87c9460123fa7f897b69fdee7, https://ubuntu.com/security/notices/USN-6127-1, https://ubuntu.com/security/notices/USN-6130-1, https://ubuntu.com/security/notices/USN-6131-1, https://ubuntu.com/security/notices/USN-6132-1, https://ubuntu.com/security/notices/USN-6135-1, https://ubuntu.com/security/notices/USN-6149-1, https://ubuntu.com/security/notices/USN-6150-1, https://ubuntu.com/security/notices/USN-6162-1, https://ubuntu.com/security/notices/USN-6173-1, https://ubuntu.com/security/notices/USN-6175-1, https://ubuntu.com/security/notices/USN-6186-1, https://ubuntu.com/security/notices/USN-6222-1, https://ubuntu.com/security/notices/USN-6256-1, https://ubuntu.com/security/notices/USN-6385-1, https://ubuntu.com/security/notices/USN-6460-1, https://www.cve.org/CVERecord?id=CVE-2023-1380
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
