The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.12.3 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted NL80211_CMD_FRAME Netlink packet.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.19 | 4.1.43 |
| linux / linux_kernel | 4.2 | 4.4.78 |
| linux / linux_kernel | 4.5 | 4.9.39 |
| linux / linux_kernel | 4.10 | 4.11.12 |
| linux / linux_kernel | 4.12 | 4.12.3 |
| linux / linux_kernel | 3.9 | 3.10.108 |
| linux / linux_kernel | 3.11 | 3.16.48 |
| linux / linux_kernel | 3.17 | 3.18.62 |