CVE-2019-14901: Buffer Overflow
A flaw was found in the Linux kernel's Marvell wifi chip driver. A heap overflow in mwifiexprocesstdlsactionframe function in marvell/mwifiex/tdls.c allows remote attackers to cause a denial of service(system crash) or execute arbitrary code. the station receive a tdls setup request or respone frame which the EIDSUPPRATES IE 's length is larger than 32 will cause Heap Overflow.
Other sources
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.
A heap overflow flaw was found in the Linux kernel's Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.
Linux Kernel is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the mwifiexprocesstdlsactionframe function in marvell/mwifiex/tdls.c. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code or cause a denial of service on the system.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-14901?
CVE-2019-14901 is considered a critical vulnerability due to its potential for system crashes and remote code execution.
How do I fix CVE-2019-14901?
To fix CVE-2019-14901, update to the recommended kernel versions provided by your Linux distribution.
What does CVE-2019-14901 affect?
CVE-2019-14901 affects the Linux kernel's Marvell wifi chip driver, specifically the mwifiex_process_tdls_action_frame function.
Can CVE-2019-14901 lead to data breaches?
Yes, CVE-2019-14901 can potentially allow remote attackers to execute arbitrary code, which may lead to data breaches.
Is CVE-2019-14901 a local or remote vulnerability?
CVE-2019-14901 is a remote vulnerability that can be exploited by attackers from outside the affected system.