Broadcom: Heap overflow in... CVE-2017-0568 CNNVD-201704-384

7.6 AV AC AU C I A
发布: 2017-04-07
修订: 2019-10-03

Broadcom produces Wi-Fi HardMAC SoCs which are used to handle the PHY and MAC layer processing. These chips are present in both mobile devices and Wi-Fi routers, and are capable of handling many Wi-Fi related events without delegating to the host OS. On Android devices, the "bcmdhd" driver is used in order to communicate with the Wi-Fi SoC (also referred to as "dongle"). Along with the regular flow of frames transferred between the host and the dongle, the two communicate with one another via a set of "ioctls" which can be issued to read or write dongle configuration from the host. This information is exchanged using the SDIO "control" channel (`SDPCM_CONTROL_CHANNEL`) rather than the regular "data" and "glom" channels (which are used to transfer frames). When the "bcmdhd" driver performs a network scan, it does so by calling "`wl_run_escan`". In configurations where P2P scan is enabled (non-legacy configurations), the function first fetches the list of allowed channels in the...

0%
暂无可用Exp或PoC
当前有2条受影响产品信息