¡¾Ô´´Îó²î¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯Îó²î£¨CVE-2019-3846/CVE-2019-10126£©
Ðû²¼Ê±¼ä 2019-06-10Îó²î¸ÅÊö
Marvell Avastar802.11acµÍ¹¦ºÄÎÞÏßоƬϵÁÐÖ÷ÒªÓ¦ÓÃÓÚÌõ¼Ç±¾µçÄÔ¡¢ÖÇÄÜÊÖ»ú¡¢ÓÎÏ·×°±¸¡¢Â·ÓÉÆ÷ºÍÎïÁªÍø×°±¸µÈ£¬ÈçSurface Pro¡¢Surface laptop¡¢Samsung Chromebook¡¢Galaxy J1¡¢Sony PlayStation 4¡¢Xbox One¡£
Îó²îÓ°Ïì¹æÄ£
Îó²îÆÊÎö
ÆäÖУ¬Type×ֶ㤶ÈΪ1¸ö×Ö½Ú£¬³£¼ûµÄIEÀàÐÍÒÔ¼°È¡ÖµÈçÏ£º
CVE-2019-3846Ô¶³Ì¶ÑÒç³öÎó²î
Îó²î´¥·¢µÄº¯ÊýŲÓÃÁ´£º
->mwifiex_cfg80211_assoc [mwifiex]
->mwifiex_bss_start [mwifiex]
->mwifiex_fill_new_bss_desc [mwifiex]
->mwifiex_update_bss_desc_with_ie [mwifiex]
¹¥»÷ÕßÎÞÐèÕæʵAPÃÜÂ룬ֻÐèʹvictim STA¶Ï¿ªÔÓÐÅþÁ¬£¬ÊµÑéÅþÁ¬FakeAPʱ£¬¼´¿É´¥·¢¸ÃÎó²î¡£
CVE-2019-10126ÍâµØ¶ÑÒç³öÎó²î
Óû§Ì¬Ó¦ÓóÌÐò£¨Èçwpa_suppliant,hostapd£©Í¨¹ýnetlink½Ó¿ÚÓëÄÚºËÄ£¿é¾ÙÐÐͨѶ¡£ÔÚ³õʼ»¯Àú³ÌÖÐ×¢²áÐÂÎÅÏÂÁîºÍ»Øµ÷º¯Êý¡£
ÄÚºËÊÕµ½NL80211_CMD_START_APÐÂÎÅʱ£¬º¯ÊýŲÓÃÁ´£º
->rdev_start_ap [cfg80211]
->mwifiex_cfg80211_start_ap [mwifiex]
->mwifiex_set_mgmt_ies [mwifiex]
->mwifiex_uap_parse_tail_ies [mwifiex]
Çå¾²½¨Òé
Linux¸÷¿¯ÐаæÎó²îͨ¸æ£º
https://access.redhat.com/security/cve/cve-2019-3846
https://security-tracker.debian.org/tracker/CVE-2019-10126
²¹¶¡Á´½Ó£º
https://patchwork.kernel.org/patch/10970141/