CVE-2019-9503

Published: 12 April 2019

The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver receives the firmware event frame from the host, the appropriate handler is called. This frame validation can be bypassed if the bus used is USB (for instance by a wifi dongle). This can allow firmware event frames from a remote source to be processed. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

From the Ubuntu security team

Hugues Anguelkov discovered that the Broadcom Wifi driver in the Linux kernel did not properly prevent remote firmware events from being processed for USB Wifi devices. A physically proximate attacker could use this to send firmware events to the device.

Priority

Medium

CVSS 3 base score: 8.3

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-50.54)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-157.185)
Ubuntu 14.04 ESM (Trusty Tahr) Ignored
(was needed ESM criteria)
Patches:
Introduced by 5b435de0d786869c95d1962121af0d7df2542009
Fixed by a4176ec356c73a46c07c181c6d04039fafa34a9f
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1039.41)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1090.101)
Ubuntu 14.04 ESM (Trusty Tahr) Ignored
(was needed ESM criteria)
linux-aws-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1039.41~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-azure
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.18.0-1018.18~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1045.49)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (4.15.0-1045.49~14.04.1)
linux-azure-edge
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.18.0-1018.18~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1045.49)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-euclid
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(was needed ESM criteria)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-flo
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(abandoned)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [abandoned])
linux-gcp
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1032.34)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1032.34~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gcp-edge
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.18.0-1011.12~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gke
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end-of-life)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gke-4.15
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1032.34)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gke-5.0
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.0.0-1011.11~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-goldfish
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end-of-life)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [abandoned])
linux-grouper
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [abandoned])
linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.18.0-20.21~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-50.54~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.0.0-15.16~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-50.54~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-kvm
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1034.34)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1052.59)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-lts-utopic
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [end-of-life])
linux-lts-vivid
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [end-of-life])
linux-lts-wily
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [end-of-life])
linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Ignored
(was needed ESM criteria)
linux-maguro
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [abandoned])
linux-mako
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(abandoned)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [abandoned])
linux-manta
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [abandoned])
linux-oem
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1038.43)
Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(was needs-triage now end-of-life)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-oracle
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1013.15)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1013.15~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1036.38)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1117.126)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (5.1~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1053.57)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1121.127)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist