Three vulnerabilities in the marvell wifi driver included in the Linux kernel

In the driver for wireless devices based on Marvell chips identified three vulnerabilities (CVE-2019-14814, CVE-2019-14815, CVE-2019-14816), which can cause data to be written outside the allocated buffer when processing specially crafted packets sent through the interface netlink.

Issues can be exploited by a local user to cause a kernel crash on systems using Marvell wireless cards. The possibility of exploiting vulnerabilities to elevate their privileges in the system is also not ruled out. Problems are still unfixed in distributions (Debian, Ubuntu, Fedora, RHEL, SUSE). Suggested for inclusion in the Linux kernel patch.

Source: opennet.ru

Add a comment