CVE-2023-1380High· 7.1▾ TwilightA slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buf…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 3.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
17%
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
enterprise_linux = 8.0enterprise_linux = 9.0linux_kernel >= 3.2.1, < 4.14.315linux_kernel >= 4.19, < 4.19.283linux_kernel >= 5.4, < 5.4.243linux_kernel >= 5.10, < 5.10.180linux_kernel >= 5.15, < 5.15.110linux_kernel >= 6.1, < 6.1.27linux_kernel >= 6.2, < 6.2.14linux_kernel = 6.3h500s_firmwareh700s_firmwareh410s_firmwareh410c_firmwareh300s_firmwaredebian_linux = 10.0debian_linux = 11.0ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 20.04ubuntu_linux = 22.04Upgrade past the affected range:
linux_kernel 6.2.14Connected by shared product, vendor, weakness, or advisory.
CVE-2023-3268High· 7.1An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs
CVE-2025-5318Medium· 5.4A flaw was found in the libssh library in versions less than 0.11.2
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak
CVE-2026-15154Medium· 6.5A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI