CVE-2015-0570: Linux Kernel
High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that uses a long WPS IE element.
Affected products
- Linux Linux Kernel: from 4.0.0, up to and including 4.20.15; from 3.0.0, up to and including 3.19.8
Published 2016-05-09. Last modified 2026-06-17.