7.1
CVE-2023-1380
- EPSS 16.53%
- Veröffentlicht 27.03.2023 21:15:10
- Zuletzt bearbeitet 18.09.2026 01:16:55
- Erkennungen
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Linux ≫ Linux Kernel Version >= 3.2.1 < 4.14.315
Linux ≫ Linux Kernel Version >= 4.19 < 4.19.283
Linux ≫ Linux Kernel Version >= 5.4 < 5.4.243
Linux ≫ Linux Kernel Version >= 5.10 < 5.10.180
Linux ≫ Linux Kernel Version >= 5.15 < 5.15.110
Linux ≫ Linux Kernel Version >= 6.1 < 6.1.27
Linux ≫ Linux Kernel Version >= 6.2 < 6.2.14
Linux ≫ Linux Kernel Version 6.3 Update -
Linux ≫ Linux Kernel Version 6.3 Update rc1
Linux ≫ Linux Kernel Version 6.3 Update rc2
Linux ≫ Linux Kernel Version 6.3 Update rc3
Linux ≫ Linux Kernel Version 6.3 Update rc4
Linux ≫ Linux Kernel Version 6.3 Update rc5
Linux ≫ Linux Kernel Version 6.3 Update rc6
Linux ≫ Linux Kernel Version 6.3 Update rc7
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H410s Firmware Version -
Netapp ≫ H410c Firmware Version -
Netapp ≫ H300s Firmware Version -
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 22.04 SwEdition lts
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 16.53% | 0.967 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
|
| CISA-ADP | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
https://www.debian.org/security/2023/dsa-5480
https://bugzilla.redhat.com/show_bug.cgi?id=2177883
https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html
https://security.netapp.com/advisory/ntap-20230511-0001/
https://www.openwall.com/lists/oss-security/2023/03/14/1
http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html
https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang%40yonsei.ac.kr/T/#u