CVE-2023-52525
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/10a18c8bac7f60d32b7af22da03b66f350beee38Patch
- https://git.kernel.org/stable/c/16cc18b9080892d1a0200a38e36ae52e464bc555Patch
- https://git.kernel.org/stable/c/5afb996349cb6d1f14d6ba9aaa7aed3bd82534f6Patch
- https://git.kernel.org/stable/c/6b706286473db4fd54b5f869faa67f4a8cb18e99Patch
- https://git.kernel.org/stable/c/71b1d2b57f145c8469aa9346f0fd57bf59b2b89cPatch
- https://git.kernel.org/stable/c/aef7a0300047e7b4707ea0411dc9597cba108fc8Patch
- https://git.kernel.org/stable/c/b8e260654a29de872e7cb85387d8ab8974694e8ePatch
- https://git.kernel.org/stable/c/be2ff39b1504c5359f4a083c1cfcad21d666e216Patch
- https://git.kernel.org/stable/c/10a18c8bac7f60d32b7af22da03b66f350beee38Patch
- https://git.kernel.org/stable/c/16cc18b9080892d1a0200a38e36ae52e464bc555Patch
- https://git.kernel.org/stable/c/5afb996349cb6d1f14d6ba9aaa7aed3bd82534f6Patch
- https://git.kernel.org/stable/c/6b706286473db4fd54b5f869faa67f4a8cb18e99Patch
- https://git.kernel.org/stable/c/71b1d2b57f145c8469aa9346f0fd57bf59b2b89cPatch
- https://git.kernel.org/stable/c/aef7a0300047e7b4707ea0411dc9597cba108fc8Patch
- https://git.kernel.org/stable/c/b8e260654a29de872e7cb85387d8ab8974694e8ePatch
- https://git.kernel.org/stable/c/be2ff39b1504c5359f4a083c1cfcad21d666e216Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.