{"id":"CVE-2023-1380","title":"A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel","summary":"A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buf…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"redhat","product":"enterprise_linux","affected":["enterprise_linux = 8.0","enterprise_linux = 9.0","linux_kernel >= 3.2.1, < 4.14.315","linux_kernel >= 4.19, < 4.19.283","linux_kernel >= 5.4, < 5.4.243","linux_kernel >= 5.10, < 5.10.180","linux_kernel >= 5.15, < 5.15.110","linux_kernel >= 6.1, < 6.1.27","linux_kernel >= 6.2, < 6.2.14","linux_kernel = 6.3","h500s_firmware","h700s_firmware","h410s_firmware","h410c_firmware","h300s_firmware","debian_linux = 10.0","debian_linux = 11.0","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 20.04","ubuntu_linux = 22.04"],"patched":["linux_kernel 6.2.14"],"published":"2023-03-27","updated":"2026-09-18","sourceUpdated":"2026-09-18T01:16:55.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-1380","references":[{"url":"http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html","label":"secalert@redhat.com"},{"url":"http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2177883","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html","label":"secalert@redhat.com"},{"url":"https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang%40yonsei.ac.kr/T/#u","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20230511-0001/","label":"secalert@redhat.com"},{"url":"https://www.debian.org/security/2023/dsa-5480","label":"secalert@redhat.com"},{"url":"https://www.openwall.com/lists/oss-security/2023/03/14/1","label":"secalert@redhat.com"},{"url":"http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2177883","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang%40yonsei.ac.kr/T/#u","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230511-0001/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5480","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openwall.com/lists/oss-security/2023/03/14/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1380.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-1380"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1380"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1380"},{"url":"https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang@yonsei.ac.kr/T/#u"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T00:58:34.104766Z"},"epss":0.16525,"epssPercentile":0.96909,"ingestedAt":"2026-09-18T01:33:24.265Z","slug":"CVE-2023-1380","body":"## Overview\n\nA slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.\n\n## Affected\n\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `linux_kernel >= 3.2.1, < 4.14.315`\n- `linux_kernel >= 4.19, < 4.19.283`\n- `linux_kernel >= 5.4, < 5.4.243`\n- `linux_kernel >= 5.10, < 5.10.180`\n- `linux_kernel >= 5.15, < 5.15.110`\n- `linux_kernel >= 6.1, < 6.1.27`\n- `linux_kernel >= 6.2, < 6.2.14`\n- `linux_kernel = 6.3`\n- `h500s_firmware`\n- `h700s_firmware`\n- `h410s_firmware`\n- `h410c_firmware`\n- `h300s_firmware`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 20.04`\n- `ubuntu_linux = 22.04`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.2.14`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1380.json)","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":39.1,"likelihood":3.3,"exploitation":0,"ransomware":0},"changes":[]}