CVE-2023-52827
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats() len is extracted from HTT message and could be an unexpected value in case errors happen, so add validation…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats() len is extracted from HTT message and could be an unexpected value in case errors happen, so add validation before using to avoid possible out-of-bound read in the following message iteration and parsing. The same issue also applies to ppdu_info->ppdu_stats.common.num_users, so validate it before using too. These are found during code review. Compile test only.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1bc44a505a229bb1dd4957e11aa594edeea3690ePatch
- https://git.kernel.org/stable/c/79527c21a3ce04cffc35ea54f74ee087e532be57Patch
- https://git.kernel.org/stable/c/c9e44111da221246efb2e623ae1be40a5cf6542cPatch
- https://git.kernel.org/stable/c/1bc44a505a229bb1dd4957e11aa594edeea3690ePatch
- https://git.kernel.org/stable/c/79527c21a3ce04cffc35ea54f74ee087e532be57Patch
- https://git.kernel.org/stable/c/c9e44111da221246efb2e623ae1be40a5cf6542cPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.