Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Out-of-bounds read in morse.ko Vendor IE processing
Vulnerability Description
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a crafted 802.11ah beacon or probe response frame containing a malformed Vendor Information Element. The function morse_vendor_find_vendor_ie() does not validate the IE length against the expected structure size before its result is passed to morse_vendor_rx_caps_ops_ie() and morse_vendor_fill_sta_vendor_info(), which read at fixed offsets into the IE data. Because the length check only requires the IE to be longer than 3 bytes, an attacker can supply an undersized IE, causing a heap out-of-bounds read of up to 9 bytes. No authentication, association, or user interaction is required.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Morse Micro HaLowLink 安全漏洞
Vulnerability Description
Morse Micro HaLowLink是Morse Micro公司的一系列长距离无线网关设备。 Morse Micro HaLowLink 2 2.11.12之前版本存在安全漏洞,该漏洞源于morse.ko HaLow Wi-Fi内核驱动中morse_vendor_find_vendor_ie函数未验证IE长度,导致堆越界读取最多9字节,未经身份验证的攻击者可通过特制802.11ah信标或探测响应帧泄露少量内核堆内存或造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A