CVE-2019-14896

moderate-risk
Published 2019-11-27

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.

Do I need to act?

-
0.74% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

References (32)

Third Party Advisory https://usn.ubuntu.com/4225-1/
Third Party Advisory https://usn.ubuntu.com/4225-2/
Third Party Advisory https://usn.ubuntu.com/4226-1/
Third Party Advisory https://usn.ubuntu.com/4227-1/
Third Party Advisory https://usn.ubuntu.com/4227-2/
Third Party Advisory https://usn.ubuntu.com/4228-1/
Third Party Advisory https://usn.ubuntu.com/4228-2/
and 12 more references
49
/ 100
moderate-risk
Severity 32/34 · Critical
Exploitability 2/34 · Minimal
Exposure 15/34 · Moderate