CVE-2023-52525

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 2, 2024
Updated: Jan 13, 2025
CWE ID 125

Summary

CVE-2023-52525 is a vulnerability affecting the Linux kernel's wifi driver, specifically the mwifiex component. The issue involved a failure to properly check conditions when processing RFC1042 headers in incoming packets. This flaw could allow an attacker to potentially inject out-of-bound data and cause the driver to crash or behave unexpectedly. The vulnerability has been addressed by only excluding the code path that attempts to access RFC1042 headers when the buffer is too small, allowing the driver to process packets without these headers safely.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share