Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-52827

Description

In the Linux kernel, the following vulnerability has been resolved:wifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats()len is extracted from HTT message and could be an unexpected value incase errors happen, so add validation before using to avoid possibleout-of-bound read in the following message iteration and parsing.The same issue also applies to ppdu_info->ppdu_stats.common.num_users,so validate it before using too.These are found during code review.Compile test only.

POC

Reference

No PoCs from references.

Github

- https://github.com/robertsirc/sle-bci-demo