Back

CVE-2019-14896

CRITICAL

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.

Published: Nov 27, 2019 Modified: Jun 17, 2026
CWE-122 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (14)

Vendor Product Version
linux linux_kernel * ≥ 2.6.32 < 3.16.83
linux linux_kernel * ≥ 3.17 < 4.4.212
linux linux_kernel * ≥ 4.5 < 4.9.212
linux linux_kernel * ≥ 4.10 < 4.14.169
linux linux_kernel * ≥ 4.15 < 4.19.100
linux linux_kernel * ≥ 4.20 < 5.4.16
fedoraproject fedora 30
fedoraproject fedora 31
redhat enterprise_linux 6.0
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 19.10
debian debian_linux 8.0

GitHub Security Advisory GHSA-93c5-v3v3-mpq3

A vulnerability was found in marvell wifi chip driver in Linux kernel. There is a heap-based...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 8.67%

Top 5% most likely to be exploited

Threat Score 41.8 / 100

Data Sources

NVD EPSS GitHub