Vulnerabilities in Broadcom WiFi chip drivers allow remote attacks on the system

In the drivers for Broadcom wireless chips seven vulnerabilities have been identified four a vulnerability. In the simplest case, vulnerabilities can be exploited for remote denial-of-service, but scenarios are not excluded where exploits could allow an unauthenticated attacker to execute their code with Linux kernel privileges through the sending of specially crafted packets.

The problems were identified during the reverse engineering of Broadcom firmware. The vulnerable chips are widely used in laptops, smartphones, and various consumer devices, from Smart TVs to Internet of Things devices. In particular, Broadcom chips are used in smartphones from manufacturers such as Apple, Samsung, and Huawei. Notably, Broadcom was notified of the vulnerabilities back in September 2018, but it took about 7 months to coordinate the release of patches with hardware manufacturers.

Two vulnerabilities affect the internal firmware and potentially allow code execution in the operating environment used in Broadcom chips, enabling attacks on environments that do not use Linux (for example, an attack on Apple devices has been confirmed, CVE-2019-8564). It is worth noting that some Broadcom Wi-Fi chips serve as specialized processors (ARM Cortex R4 or M3), on which a semblance of their operating system runs with implementations of their wireless stack 802.11 (FullMAC). In such chips, the driver facilitates interaction between the main system and the Wi-Fi chip firmware. To gain full control over the main system after compromising FullMAC, it is recommended to use additional vulnerabilities or, on some chips, to take advantage of full access to the system memory. In chips with SoftMAC, the 802.11 wireless stack is implemented on the driver side and is executed using the system CPU.

Vulnerabilities in Broadcom WiFi chip drivers allow remote attacks on the system

Vulnerabilities in the drivers are manifested both in the proprietary wl driver (SoftMAC and FullMAC) and in the open-source brcmfmac (FullMAC). Two buffer overflows have been identified in the wl driver, exploited during the transmission of specially crafted EAPOL messages during the connection negotiation process (an attack can be carried out when connecting to a malicious access point). In the case of the SoftMAC chip, vulnerabilities lead to a compromise of the system kernel, whereas in the case of FullMAC, code can be executed on the firmware side. The brcmfmac driver has a buffer overflow and a frame processing error, which can be exploited by sending control frames. There are issues in the brcmfmac driver in the Linux kernel. existed four vulnerabilities have been fixed in February.

Identified vulnerabilities:

  • CVE-2019-9503 — Incorrect behavior of the brcmfmac driver when processing control frames used for firmware interactions. When a firmware event frame comes from an external source, the driver discards it; however, if the event is received via the internal bus, the frame is allowed through. The problem is that events from USB devices are transmitted over the internal bus, allowing attackers to successfully send firmware control frames when using wireless adapters with USB interfaces.
  • CVE-2019-9500 — Enabling the "Wake-up on Wireless LAN" feature can trigger a heap overflow in the brcmfmac driver (brcmf_wowl_nd_results function) by sending a specially crafted control frame. This vulnerability can be used to execute code in the main system after compromising the chip or in combination with the CVE-2019-9503 vulnerability to bypass checks during the remote sending of a control frame.
  • CVE-2019-9501 — Buffer overflow in the wl driver (wlc_wpa_sup_eapol function) occurring when processing messages whose manufacturer information field exceeds 32 bytes.
  • CVE-2019-9502 — Buffer overflow in the wl driver (wlc_wpa_plumb_gtk function) occurring when processing messages whose manufacturer information field exceeds 164 bytes.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster