CVE-2019-14897
29.11.2019, 15:15
A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 2.6.32 ≤ 𝑥 < 3.16.83 |
linux | linux_kernel | 3.17 ≤ 𝑥 < 4.4.212 |
linux | linux_kernel | 4.5 ≤ 𝑥 < 4.9.212 |
linux | linux_kernel | 4.10 ≤ 𝑥 < 4.14.169 |
linux | linux_kernel | 4.15 ≤ 𝑥 < 4.19.100 |
linux | linux_kernel | 4.20 ≤ 𝑥 < 5.4.16 |
debian | debian_linux | 8.0 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||||||
linux-aws |
| ||||||||||||
linux-aws-5.0 |
| ||||||||||||
linux-aws-hwe |
| ||||||||||||
linux-azure |
| ||||||||||||
linux-azure-5.3 |
| ||||||||||||
linux-azure-edge |
| ||||||||||||
linux-gcp |
| ||||||||||||
linux-gcp-5.3 |
| ||||||||||||
linux-gcp-edge |
| ||||||||||||
linux-gke-4.15 |
| ||||||||||||
linux-gke-5.0 |
| ||||||||||||
linux-gke-5.3 |
| ||||||||||||
linux-hwe |
| ||||||||||||
linux-hwe-edge |
| ||||||||||||
linux-kvm |
| ||||||||||||
linux-lts-trusty |
| ||||||||||||
linux-lts-xenial |
| ||||||||||||
linux-oem |
| ||||||||||||
linux-oem-5.6 |
| ||||||||||||
linux-oem-osp1 |
| ||||||||||||
linux-oracle |
| ||||||||||||
linux-oracle-5.0 |
| ||||||||||||
linux-oracle-5.3 |
| ||||||||||||
linux-raspi2 |
| ||||||||||||
linux-raspi2-5.3 |
| ||||||||||||
linux-snapdragon |
|
Common Weakness Enumeration
- CWE-121 - Stack-based Buffer OverflowA stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
References