cve/2024/CVE-2024-50008.md
2025-09-29 21:09:30 +02:00

1.2 KiB

CVE-2024-50008

Description

In the Linux kernel, the following vulnerability has been resolved:wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()Replace one-element array with a flexible-array member instruct host_cmd_ds_802_11_scan_ext.With this, fix the following warning:elo 16 17:51:58 surfacebook kernel: ------------[ cut here ]------------elo 16 17:51:58 surfacebook kernel: memcpy: detected field-spanning write (size 243) of single field "ext_scan->tlv_buffer" at drivers/net/wireless/marvell/mwifiex/scan.c:2239 (size 1)elo 16 17:51:58 surfacebook kernel: WARNING: CPU: 0 PID: 498 at drivers/net/wireless/marvell/mwifiex/scan.c:2239 mwifiex_cmd_802_11_scan_ext+0x83/0x90 [mwifiex]

POC

Reference

No PoCs from references.

Github