Buffer overflow in Linux kernel - CVE-2019-16746
Published: September 24, 2019 / Updated: November 3, 2022
Vulnerability identifier: #VU92779
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-16746
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
Affected software
Linux kernel
Slackware Linux
Fedora
linux-4.4.199/kernel-generic
linux-4.4.199/kernel-huge
linux-4.4.199/kernel-modules
linux-4.4.199/kernel-headers
kernel
kernel-headers
kernel-tools
Slackware Linux
Fedora
linux-4.4.199/kernel-generic
linux-4.4.199/kernel-huge
linux-4.4.199/kernel-modules
linux-4.4.199/kernel-headers
kernel
kernel-headers
kernel-tools
How to mitigate CVE-2019-16746
Install update from vendor's repository.
linux-4.4.199/kernel-generic - update to 4.4.199
linux-4.4.199/kernel-huge - update to 4.4.199
linux-4.4.199/kernel-modules - update to 4.4.199
linux-4.4.199/kernel-headers - update to 4.4.199_smp
kernel - addressed in versions 5.3.6-200.fc30, 5.3.6-300.fc31
kernel-headers - addressed in versions 5.3.6-200.fc30, 5.3.6-300.fc31
kernel-tools - addressed in versions 5.3.6-200.fc30, 5.3.6-300.fc31
linux-4.4.199/kernel-huge - update to 4.4.199
linux-4.4.199/kernel-modules - update to 4.4.199
linux-4.4.199/kernel-headers - update to 4.4.199_smp
kernel - addressed in versions 5.3.6-200.fc30, 5.3.6-300.fc31
kernel-headers - addressed in versions 5.3.6-200.fc30, 5.3.6-300.fc31
kernel-tools - addressed in versions 5.3.6-200.fc30, 5.3.6-300.fc31
External References
- https://marc.info/?l=linux-wireless&m=156901391225058&w=2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TASE2ESEZAER6DTZH3DJ4K2JNO46TVL7/
- https://security.netapp.com/advisory/ntap-20191031-0005/
- https://seclists.org/bugtraq/2019/Nov/11
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- https://usn.ubuntu.com/4186-1/
- https://usn.ubuntu.com/4183-1/
- https://usn.ubuntu.com/4210-1/
- https://usn.ubuntu.com/4209-1/
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html
- https://www.oracle.com/security-alerts/cpuApr2021.html