Skip to content

[SECURITY] cfg80211: wext: avoid copying malformed SSIDs (CVE-2019-17133)#128

Open
Mifacopy wants to merge 1 commit intofacebookincubator:oculus-go-kernel-masterfrom
Mifacopy:patch-25
Open

[SECURITY] cfg80211: wext: avoid copying malformed SSIDs (CVE-2019-17133)#128
Mifacopy wants to merge 1 commit intofacebookincubator:oculus-go-kernel-masterfrom
Mifacopy:patch-25

Conversation

@Mifacopy
Copy link

Fix CVE-2019-17133.

Upstream commit: 4ac2813cc867ae563a1ba5a9414bfb554e5796fa

cfg80211_mgd_wext_giwessid() did not reject an overly long SSID information
element before copying it to userspace, leading to a buffer overflow.

Add a bounds check against IW_ESSID_MAX_SIZE prior to memcpy() and propagate
-EINVAL on invalid length.

Reference: CVE-2019-17133

@meta-cla meta-cla bot added the CLA Signed Do not delete this pull request or issue due to inactivity. label Feb 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed Do not delete this pull request or issue due to inactivity.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant