CVE-2023-54286

Linux Kernel - Buffer Overflow in iwlwifi DVM TKIP Key Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace A received TKIP key may be up to 32 bytes because it may contain MIC rx/tx keys too. These are not used by iwl and copying these over overflows the iwl_keyinfo.key field. Add a check to not copy more data to iwl_keyinfo.key then will fit. This fixes backtraces like this one: memcpy: detected field-spanning write (size 32) of single field "sta_cmd.key.key" at drivers/net/wireless/intel/iwlwifi/dvm/sta.c:1103 (size 16) WARNING: CPU: 1 PID: 946 at drivers/net/wireless/intel/iwlwifi/dvm/sta.c:1103 iwlagn_send_sta_key+0x375/0x390 [iwldvm] <snip> Hardware name: Dell Inc. Latitude E6430/0H3MT5, BIOS A21 05/08/2017 RIP: 0010:iwlagn_send_sta_key+0x375/0x390 [iwldvm] <snip> Call Trace: <TASK> iwl_set_dynamic_key+0x1f0/0x220 [iwldvm] iwlagn_mac_set_key+0x1e4/0x280 [iwldvm] drv_set_key+0xa4/0x1b0 [mac80211] ieee80211_key_enable_hw_accel+0xa8/0x2d0 [mac80211] ieee80211_key_replace+0x22d/0x8e0 [mac80211] <snip>

Scores

EPSS 0.0018
EPSS Percentile 8.3%

Details

Status published
Products (25)
linux/Kernel 3.1.0 - 4.14.316linux
linux/Kernel 4.15.0 - 4.19.284linux
linux/Kernel 4.20.0 - 5.4.244linux
linux/Kernel 5.11.0 - 5.15.113linux
linux/Kernel 5.16.0 - 6.1.30linux
linux/Kernel 5.5.0 - 5.10.181linux
linux/Kernel 6.2.0 - 6.3.4linux
Linux/Linux < 3.1
Linux/Linux 3.1
Linux/Linux 4.14.316 - 4.14.*
... and 15 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026