Rapid7 Vulnerability & Exploit Database

Centos Linux: CVE-2019-9503: Important: kernel security and bug fix update (Multiple Advisories)

Back to Search

Centos Linux: CVE-2019-9503: Important: kernel security and bug fix update (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
09/10/2019
Created
09/12/2019
Added
09/11/2019
Modified
09/12/2019

Description

If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and not be processed. If the driver receives the firmware event frame from the host, the appropriate handler is called. This frame validation can be bypassed if the bus used is USB (for instance by a WiFi dongle). This can allow firmware event frames from a remote source to be processed and this can result in denial of service (DoS) condition.

Solution(s)

  • centos-upgrade-kernel
  • centos-upgrade-kernel-rt

References

  • centos-upgrade-kernel
  • centos-upgrade-kernel-rt

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;