Unpatched Linux bug may open devices to serious attacks over Wi-Fi

Peter Reutemann <[email protected]> Fri, 18 Oct 2019 16:29:56 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+hseAX1Ye9uipsoUXLDvnii0Z0Z0Crr733_D=c0wRzVw@mail.gmail.com>
'A potentially serious vulnerability in Linux may make it possible for
nearby devices to use Wi-Fi signals to crash or fully compromise
vulnerable machines, a security researcher said.

The flaw is located in the RTLWIFI driver, which is used to support
Realtek Wi-Fi chips in Linux devices. The vulnerability triggers a
buffer overflow in the Linux kernel when a machine with a Realtek
Wi-Fi chip is within radio range of a malicious device. At a minimum,
exploits would cause an operating-system crash and could possibly
allow a hacker to gain complete control of the computer. The flaw
dates back to version 3.10.1 of the Linux kernel released in 2013.

"The bug is serious," Nico Waisman, who is a principal security
engineer at Github, told Ars. "It's a vulnerability that triggers an
overflow remotely through Wi-Fi on the Linux kernel, as long as you're
using the Realtek (RTLWIFI) driver."

The vulnerability is tracked as CVE-2019-17666. Linux developers
proposed a fix on Wednesday that will likely be incorporated into the
OS kernel in the coming days or weeks. Only after that will the fix
make its way into various Linux distributions.'

-- source: https://arstechnica.com/information-technology/2019/10/unpatched-linux-flaw-may-let-attackers-crash-or-compromise-nearby-devices/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz