Pixel Security: WLAN firmware to AP Kernel integer underflow cause memcpy overwrite in function wl_notify_rx_mgmt_frame
Details
In wlnotifyrxmgmtframe of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.