Hide Forgot
The Mwifiex driver implementation in the Linux kernel has a memory leak on the error condition when encountering an error condition when in 'Wifi test mode'. Wifi test mode is a 'region' mode that wireless devices can use that allows for full use of the wifi spectrum disregarding regional laws that prohibit broadcasting in certain ranges. This requires a connection to another wifi device in "test mode" to create the error condition. Reference and upstream commit: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=003b686ace820ce2d635a83f10f2d7f9c147dabc
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1791955]
This was fixed for Fedora in the 5.1.6 stable kernel updates.
Mitigation: As connecting to a wireless device is not automatic and initiated by a user, not connecting to rogue access points would prevent this flaw from being abused.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1493 https://access.redhat.com/errata/RHSA-2020:1493
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-20095
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:4062 https://access.redhat.com/errata/RHSA-2020:4062
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:4060 https://access.redhat.com/errata/RHSA-2020:4060