UBUNTU-CVE-2019-9500
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
02 / AFFECTED SOFTWARE
Affected packages
11 explicit affected versions
6 explicit affected versions
34 explicit affected versions
29 explicit affected versions
49 explicit affected versions
5 explicit affected versions
28 explicit affected versions
23 explicit affected versions
24 explicit affected versions
21 explicit affected versions
6 explicit affected versions
1 explicit affected versions
6 explicit affected versions
22 explicit affected versions
19 explicit affected versions
5 explicit affected versions
24 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
05 / REFERENCES
Further evidence
- https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
- https://ubuntu.com/security/CVE-2019-9500
- https://ubuntu.com/security/notices/USN-3979-1
- https://ubuntu.com/security/notices/USN-3980-1
- https://ubuntu.com/security/notices/USN-3980-2
- https://ubuntu.com/security/notices/USN-3981-1
- https://ubuntu.com/security/notices/USN-3981-2
- https://www.cve.org/CVERecord?id=CVE-2019-9500