Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 3 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
wifi: wcn36xx: fix heap overflow from oversized firmware HAL response

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length.

Affected products

Linux
  • <88a240d86d3d64521f9194abe185ac71cc74d0bd
  • ==3.13
  • <cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92
  • =<6.6.*
  • <18813b90032bfaafb225906a4d2b51be4dfc02c3
  • =<*
  • <15545ee71301e82d26d9a31b407ed0019eb62a60
  • <dae9cadf0925f1cbfb71306d60490890df3870a6
  • =<6.18.*
  • <1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18
  • =<6.12.*
  • <3.13
  • =<7.1.*
  • =<6.1.*