---
id: CVE-2023-1380
title: >-
  A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in
  drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux
  Kernel
summary: >-
  A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in
  drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux
  Kernel. This issue could occur when assoc_info->req_len data is bigger than
  the size of the buf…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: redhat
product: enterprise_linux
affected:
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - 'linux_kernel >= 3.2.1, < 4.14.315'
  - 'linux_kernel >= 4.19, < 4.19.283'
  - 'linux_kernel >= 5.4, < 5.4.243'
  - 'linux_kernel >= 5.10, < 5.10.180'
  - 'linux_kernel >= 5.15, < 5.15.110'
  - 'linux_kernel >= 6.1, < 6.1.27'
  - 'linux_kernel >= 6.2, < 6.2.14'
  - linux_kernel = 6.3
  - h500s_firmware
  - h700s_firmware
  - h410s_firmware
  - h410c_firmware
  - h300s_firmware
  - debian_linux = 10.0
  - debian_linux = 11.0
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - ubuntu_linux = 20.04
  - ubuntu_linux = 22.04
patched:
  - linux_kernel 6.2.14
published: '2023-03-27'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T01:16:55.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-1380'
references:
  - url: >-
      http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
    label: secalert@redhat.com
  - url: >-
      http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2177883'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html'
    label: secalert@redhat.com
  - url: >-
      https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang%40yonsei.ac.kr/T/#u
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20230511-0001/'
    label: secalert@redhat.com
  - url: 'https://www.debian.org/security/2023/dsa-5480'
    label: secalert@redhat.com
  - url: 'https://www.openwall.com/lists/oss-security/2023/03/14/1'
    label: secalert@redhat.com
  - url: >-
      http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2177883'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang%40yonsei.ac.kr/T/#u
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230511-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5480'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2023/03/14/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1380.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-1380'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-1380'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-1380'
  - url: >-
      https://lore.kernel.org/linux-wireless/20230309104457.22628-1-jisoo.jang@yonsei.ac.kr/T/#u
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T00:58:34.104766Z'
epss: 0.16525
epssPercentile: 0.96909
ingestedAt: '2026-09-18T01:33:24.265Z'
---

## Overview

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

## Affected

- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `linux_kernel >= 3.2.1, < 4.14.315`
- `linux_kernel >= 4.19, < 4.19.283`
- `linux_kernel >= 5.4, < 5.4.243`
- `linux_kernel >= 5.10, < 5.10.180`
- `linux_kernel >= 5.15, < 5.15.110`
- `linux_kernel >= 6.1, < 6.1.27`
- `linux_kernel >= 6.2, < 6.2.14`
- `linux_kernel = 6.3`
- `h500s_firmware`
- `h700s_firmware`
- `h410s_firmware`
- `h410c_firmware`
- `h300s_firmware`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 20.04`
- `ubuntu_linux = 22.04`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.2.14`

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-1380.json)
