CVE-2023-1380
Executive Summary
A slab-out-of-bound read in the Linux kernel's Broadcom wireless driver (brcmf_get_assoc_ies) can be triggered when assoc_info->req_len exceeds WL_EXTRA_BUF_MAX, potentially causing a denial‑of‑service by corrupting memory or crashing the system. The flaw is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.1 (HIGH) - Published: 2023-03-27T21:15:10.623 - Last Modified: 2026-09-18T01:16:55.540
Original Description: A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
"Intuition will tell the thinking mind where to look next."
— Jonas Salk