← All CVEs

CVE-2023-1380

high · 7.1

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

7.1
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2023-03-27
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
redhatenterprise_linux8.0
redhatenterprise_linux9.0
linuxlinux_kernel>= 3.2.1, < 4.14.315
linuxlinux_kernel>= 4.19, < 4.19.283
linuxlinux_kernel>= 5.4, < 5.4.243
linuxlinux_kernel>= 5.10, < 5.10.180
linuxlinux_kernel>= 5.15, < 5.15.110
linuxlinux_kernel>= 6.1, < 6.1.27
linuxlinux_kernel>= 6.2, < 6.2.14
linuxlinux_kernel6.3
linuxlinux_kernel6.3
linuxlinux_kernel6.3
linuxlinux_kernel6.3
linuxlinux_kernel6.3
linuxlinux_kernel6.3
linuxlinux_kernel6.3
linuxlinux_kernel6.3
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph410c_firmwareall versions
netapph410call versions
netapph300s_firmwareall versions
netapph300sall versions
debiandebian_linux10.0
debiandebian_linux11.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux20.04
canonicalubuntu_linux22.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-1380