In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping reinjected packets For fragmented packets, ath12k reassembles each fragment as a…
High CVSS 8.8
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping reinjected packets For fragmented packets, ath12k reassembles each fragment as a normal packet and then reinjects it into HW ring. In this case, the DMA direction should be DMA_TO_DEVICE, not DMA_FROM_DEVICE. Otherwise, an invalid payload may be reinjected into the HW and subsequently delivered to the host. Given that arbitrary memory can be allocated to the skb buffer, knowle…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/33322e3ef07409278a18c6919c448e369d66a18e Patch
- https://git.kernel.org/stable/c/6925320fcd40d8042d32bf4ede8248e7a5315c3b Patch
- https://git.kernel.org/stable/c/e99d9b16ff153de9540073239d24adc3b0a3a997 Patch
Timeline
- nvd_ingest NVD