Description
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Kees Cook · textlocallinux
https://www.exploit-db.com/exploits/38559
References (18)
Scores
EPSS
0.0021
EPSS Percentile
43.2%
Details
CWE
CWE-134
Status
published
Products (6)
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
12.10
canonical/ubuntu_linux
13.04
debian/debian_linux
6.0
linux/linux_kernel
2.6.12 - 3.0.83
Published
Jun 07, 2013
Tracked Since
Feb 18, 2026