Executive brief
A vulnerability exists in the Linux kernel driver for Microchip WILC1000 wireless chips, which are used to provide Wi-Fi connectivity in various embedded devices. An error in how the driver handles network connection requests could allow a remote attacker to cause a system crash or potentially access sensitive information. This issue affects the reliability and security of devices using these specific wireless components.
Technical details
The vulnerability is a 'suspicious RCU usage' flaw within the wilc1000 driver (specifically in drivers/net/wireless/microchip/wilc1000/hif.c). In the wilc_parse_join_bss_param function, the driver dereferences an RCU-protected pointer (bss->ies) without being inside an RCU read-side critical section. This lack of proper synchronization means the BSS Information Elements (IEs) could be freed or modified by another thread while being accessed, leading to a NULL pointer dereference or use-after-free. An attacker within wireless range could potentially trigger this during the connection phase. The fix involves wrapping the dereference and data copy within rcu_read_lock() and rcu_read_unlock() blocks.
Affected products
- Linux Linux Kernel 5.1 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2
Timeline
- 2024-01-05: patched: Initial patch submitted by Alexis Lothoré
- 2024-05-01: advisory: CVE-2024-27053 published
References
- https://git.kernel.org/stable/c/205c50306acf58a335eb19fa84e40140f4fe814f
- https://git.kernel.org/stable/c/4bfd20d5f5c62b5495d6c0016ee6933bd3add7ce
- https://git.kernel.org/stable/c/5800ec78775c0cd646f71eb9bf8402fb794807de
- https://git.kernel.org/stable/c/745003b5917b610352f52fe0d11ef658d6471ec2
- https://git.kernel.org/stable/c/b4bbf38c350acb6500cbe667b1e2e68f896e4b38
- https://git.kernel.org/stable/c/d80fc436751cfa6b02a8eda74eb6cce7dadfe5a2
- https://git.kernel.org/stable/c/dd50d3ead6e3707bb0a5df7cc832730c93ace3a7