Vulnerability Name: | CVE-2023-1380 (CCN-250058) | ||||||||||||||||||||
Assigned: | 2023-03-14 | ||||||||||||||||||||
Published: | 2023-03-14 | ||||||||||||||||||||
Updated: | 2023-07-27 | ||||||||||||||||||||
Summary: | Linux Kernel could allow a physical attacker to obtain sensitive information, caused by a slab-out-of-bounds read flaw in the Broadcom Full MAC Wi-Fi driver. By using a specially crafted USB device, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system. | ||||||||||||||||||||
CVSS v3 Severity: | 7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H) 6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
4.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2023-1380 Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: Issue Tracking, Mitigation, Patch, Third Party Advisory secalert@redhat.com Source: XF Type: UNKNOWN linux-kernel-cve20231380-info-disc(250058) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: lore.kernel Web site [PATCH v2] wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Source: secalert@redhat.com Type: Mailing List, Patch secalert@redhat.com Source: CCN Type: OSS Mailing List, Tue, 14 Mar 2023 10:34:35 +0900 Re: A USB-accessible slab-out-of-bounds read in Linux kernel driver Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: secalert@redhat.com Type: Mailing List, Third Party Advisory secalert@redhat.com | ||||||||||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |