¡¾Ô´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯·ì϶£¨CVE-2019-3846/CVE-2019-10126£©
°ä²¼¹¦·ò 2019-06-10·ì϶¸ÅÊö
Marvell Avastar802.11acµÍ¹¦ºÄÎÞÏßоƬϵÁÐÖØÒªÀûÓÃÓڱʼDZ¾µçÄÔ¡¢ÖÇÄÜÊÖ»ú¡¢ÓÎÏ·É豸¡¢Â·ÓÉÆ÷ºÍÎïÁªÍøÉ豸µÈ£¬£¬ÈçSurface Pro¡¢Surface laptop¡¢Samsung Chromebook¡¢Galaxy J1¡¢Sony PlayStation 4¡¢Xbox One¡£¡£
·ì϶ӰÏìÁìÓò
·ì϶·ÖÎö
ÆäÖУ¬£¬Type×ֶ㤶ÈΪ1¸ö×Ö½Ú£¬£¬³£¼ûµÄIEÀàÐÍÒÔ¼°È¡ÖµÈçÏ£º£º
CVE-2019-3846Ô¶³Ì¶ÑÒç³ö·ì϶
·ì϶´¥·¢µÄº¯ÊýŲÓÃÁ´£º£º
->mwifiex_cfg80211_assoc [mwifiex]
->mwifiex_bss_start [mwifiex]
->mwifiex_fill_new_bss_desc [mwifiex]
->mwifiex_update_bss_desc_with_ie [mwifiex]
¹¥»÷ÕßÎÞÐèÕæÊµAPÃÜÂ룬£¬Ö»Ðèʹvictim STA¶Ï¿ªÔÓÐÏνӣ¬£¬³¢ÊÔÏνÓFakeAPʱ£¬£¬¼´¿É´¥·¢¸Ã·ì϶¡£¡£
CVE-2019-10126±¾µØ¶ÑÒç³ö·ì϶
Óû§Ì¬ÀûÓ÷¨Ê½£¨Èçwpa_suppliant,hostapd£©Í¨¹ýnetlink½Ó¿ÚÓëÄÚºËÄ£¿é½øÐÐͨѶ¡£¡£ÔÚ³õʼ»¯¹ý³ÌÖÐ×¢²áÐÂÎźÅÁîºÍ»Øµ÷º¯Êý¡£¡£
ÄÚºËÊÕµ½NL80211_CMD_START_APÐÂÎÅʱ£¬£¬º¯ÊýŲÓÃÁ´£º£º
->rdev_start_ap [cfg80211]
->mwifiex_cfg80211_start_ap [mwifiex]
->mwifiex_set_mgmt_ies [mwifiex]
->mwifiex_uap_parse_tail_ies [mwifiex]
°²È«½¨Òé
Linux¸÷¿¯Ðаæ·ì϶²¼¸æ£º£º
https://access.redhat.com/security/cve/cve-2019-3846
https://security-tracker.debian.org/tracker/CVE-2019-10126
²¹¶¡Á´½Ó£º£º
https://patchwork.kernel.org/patch/10970141/


¾©¹«Íø°²±¸11010802024551ºÅ