¡¾Ô´´Â©¶´¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯Â©¶´£¨CVE-2019-3846/CVE-2019-10126£©
Ðû²¼Ê±¼ä 2019-06-10©¶´¸ÅÊö
Marvell Avastar802.11acµÍ¹¦ºÄÎÞÏßоƬϵÁÐÖ÷ÒªÓ¦ÓÃÓÚÌõ¼Ç±¾µçÄÔ¡¢ÖÇÄÜÊÖ»ú¡¢ÓÎÏ·É豸¡¢Â·ÓÉÆ÷ºÍÎïÁªÍøÉ豸µÈ£¬ÈçSurface Pro¡¢Surface laptop¡¢Samsung Chromebook¡¢Galaxy J1¡¢Sony PlayStation 4¡¢Xbox One¡£
©¶´Ó°Ï췶Χ
©¶´·ÖÎö
ÆäÖУ¬Type×ֶ㤶ÈΪ1¸ö×Ö½Ú£¬³£¼ûµÄIEÀàÐÍÒÔ¼°È¡ÖµÈçÏ£º
CVE-2019-3846Ô¶³Ì¶ÑÒç³ö©¶´
©¶´´¥·¢µÄº¯Êýµ÷ÓÃÁ´£º
->mwifiex_cfg80211_assoc [mwifiex]
->mwifiex_bss_start [mwifiex]
->mwifiex_fill_new_bss_desc [mwifiex]
->mwifiex_update_bss_desc_with_ie [mwifiex]
¹¥»÷ÕßÎÞÐèÕæʵAPÃÜÂ룬ֻÐèʹvictim STA¶Ï¿ªÔÓÐÁ¬½Ó£¬ÊµÑéÁ¬½ÓFakeAPʱ£¬¼´¿É´¥·¢¸Ã©¶´¡£
CVE-2019-10126µ±µØ¶ÑÒç³ö©¶´
Óû§Ì¬Ó¦Ó÷¨Ê½£¨Èçwpa_suppliant,hostapd£©Í¨¹ýnetlink½Ó¿ÚÓëÄÚºËÄ£¿é½øÐÐͨÐÅ¡£ÔÚ³õʼ»¯¹ý³ÌÖÐ×¢²áÏûÏ¢ÃüÁîºÍ»Øµ÷º¯Êý¡£
ÄÚºËÊÕµ½NL80211_CMD_START_APÏûϢʱ£¬º¯Êýµ÷ÓÃÁ´£º
->rdev_start_ap [cfg80211]
->mwifiex_cfg80211_start_ap [mwifiex]
->mwifiex_set_mgmt_ies [mwifiex]
->mwifiex_uap_parse_tail_ies [mwifiex]
Äþ¾²½¨Òé
Linux¸÷¿¯Ðа橶´Í¨¸æ£º
https://access.redhat.com/security/cve/cve-2019-3846
https://security-tracker.debian.org/tracker/CVE-2019-10126
²¹¶¡Á´½Ó£º
https://patchwork.kernel.org/patch/10970141/