CVE-2019-14895: Buffer Overflow
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.
Other sources
A heap-based buffer overflow was discovered in the Linux kernel's Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.
A vulnerability was found in marvell wifi chip driver in Linux kernel. There is a heap-based buffer overflow while attempting a connection negotiation during the handling of the remote devices country settings ( When STA connects to AP, mwifiexprocesscountryie function will be called for STA ). This could allow the remote device to cause a denial of service(system crash) or possibly execute arbitrary code.
— Red Hat
Linux Kernel is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the mwifiexprocesscountryie function in drivers/net/wireless/marvell/mwifiex/staioctl.c. By sending a specially-crafted beacon packet, a remote attacker could overflow a buffer and execute arbitrary code or cause a denial of service on the system.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-14895?
CVE-2019-14895 has been assigned a high severity rating due to the potential for remote code execution via a heap-based buffer overflow.
How do I fix CVE-2019-14895?
To fix CVE-2019-14895, update the Linux kernel to version 4.18.0 or later or apply the specific patches provided by your distribution.
Which versions of the Linux kernel are affected by CVE-2019-14895?
CVE-2019-14895 affects all versions of the Linux kernel 3.x.x and 4.x.x prior to 4.18.0.
What systems are impacted by CVE-2019-14895?
CVE-2019-14895 impacts systems using the Marvell WiFi chip driver in various Linux kernel versions.
Was CVE-2019-14895 disclosed publicly?
Yes, CVE-2019-14895 was disclosed publicly as part of security vulnerability announcements in 2019.