A slab-out-of-bound read problem was found in brcmfgetassocies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when associnfo->reqlen data is bigger than the size of the buffer, defined as WLEXTRABUFMAX, leading to a denial of service.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "3.2.1"
},
{
"fixed": "4.14.315"
}
]
},
{
"events": [
{
"introduced": "4.19"
},
{
"fixed": "4.19.283"
}
]
},
{
"events": [
{
"introduced": "5.4"
},
{
"fixed": "5.4.243"
}
]
},
{
"events": [
{
"introduced": "5.10"
},
{
"fixed": "5.10.180"
}
]
},
{
"events": [
{
"introduced": "5.15"
},
{
"fixed": "5.15.110"
}
]
},
{
"events": [
{
"introduced": "6.1"
},
{
"fixed": "6.1.27"
}
]
},
{
"events": [
{
"introduced": "6.2"
},
{
"fixed": "6.2.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3-rc7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.04"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1380.json"