A flaw array-index-out-of-bounds in the Linux Kernel found in drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c. When attaching malicious USB device, buffer overflow could happen in the Broadcom Full MAC Wi-Fi driver. The bug occurs in brcmf_fweh_event_worker, when emsg.bsscfgidx, data from an URB provided by a USB device, is bigger than the size of the array drvr->iflist. References: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c?id=6788ba8aed4e28e90f72d68a9d794e34eac17295 https://seclists.org/oss-sec/2022/q4/60
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2150961]
This was fixed for Fedora with the 6.0.8 stable kernel updates.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:2148 https://access.redhat.com/errata/RHSA-2023:2148
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:2458 https://access.redhat.com/errata/RHSA-2023:2458
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:2736 https://access.redhat.com/errata/RHSA-2023:2736
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:2951 https://access.redhat.com/errata/RHSA-2023:2951
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-3628