Remotely exploitable vulnerability in Linux driver for Realtek chips

In the Linux kernel driver rtlwifi for wireless adapters using Realtek chips identified vulnerability (CVE-2019-17666), which can potentially be exploited to execute code in the kernel context by sending specially crafted frames.

The vulnerability is caused by a buffer overflow in the P2P mode (Wifi-Direct) implementation. When parsing frames NoA (Notice of Absence) lacks a check on the size of one of the values, allowing the tail of data to be written beyond the buffer and overwrite information in the subsequent kernel structures.

An attack can be carried out by sending specially crafted frames to a system with an active Realtek chip-based network adapter that supports Wi-Fi Direct, allowing two wireless adapters to connect directly without an access point. To exploit the issue, the attacker does not need to connect to the wireless network, nor does the user need to take any action; it is sufficient for the attacker to be within the coverage area of the wireless signal.

The working prototype of the exploit currently only leads to a remote kernel crash, but the vulnerability potentially allows for code execution (this is still just a theoretical assumption, as there is no existing code execution exploit prototype yet, but the researcher who identified the issue is already working working on its creation).

The issue manifests starting from the kernel 3.12 (according to other data, the issue manifests starting from the kernel 3.10), released in 2013. The fix is currently available only in the form of a patch. In the distributions, the issue remains unpatched.
You can track the progress of vulnerability fixes in distributions at the following pages: Debian, Arch, SUSE/openSUSE, Ubuntu, Arch Linux, Alpine. The vulnerability likely also affects affects and the Android platform.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster