Jump to content

Summary

Linux kernels from 5.1 through the latest (as of today, 2022 October 14) have a wifi vulnerability which allows a remote attacker to set up a wifi network and gain control of the linux kernel.

 

Note that your Android device does not have to join their network, just be scanning in the vicinity of the attacker.

 

Quotes

Quote

CVE-2022-41674

 

This vulnerability was introduced in v5.1-rc1 and leads to a heap overflow. Compiled with CONFIG_SLUB_DEBUG_ON the kernel emits the following among other errors:

 

(memory corruption error)

 

My thoughts

Today is a bad day to be using Android. I use Android. I'm turning off my wifi. For at least the next month or so.

 

Sources

https://lwn.net/Articles/911062/

https://lwn.net/ml/oss-security/20221013101046.GB20615@suse.de/

https://github.com/PurpleVsGreen/beacown

Link to comment
https://linustechtips.com/topic/1461092-linux-wifi-stack-exploit-beacown/
Share on other sites

Link to post
Share on other sites

Somewhat unrelated... 

 

wth is with this embed? 

 

image.png.070f70cc2a23d8bc922429b36343a5b6.png

 

Also, now to the thing... let's hope a fix is pushed asap... 

 

As a android and linux users I have to say this is quite concerning 

If someone has helped you out on the forum don't forget to give them a reaction to say thank you!

 

The only true wisdom is in knowing you know nothing. - Socrates
 

Please put as much effort into your question as you expect me to put into answering it. 

Link to post
Share on other sites

I could have sworn there was something similar in the way the kernel was built many many many years ago and it was used to exploit the wifi cards on mobile devices

 

Edit here it is:

https://blogs.blackberry.com/en/2017/08/broadpwn-the-mobile-exploit-for-android-and-iphones

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×