CVE-2023-1380: Canonical Ubuntu Linux

High severity, CVSS 7.1. EPSS: 16.5% chance of exploitation in the next 30 days.

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only; version 22.04 only
  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Linux Linux Kernel: from 3.2.1, before 4.14.315 (fixed in 4.14.315); from 4.19, before 4.19.283 (fixed in 4.19.283); from 5.4, before 5.4.243 (fixed in 5.4.243); from 5.10, before 5.10.180 (fixed in 5.10.180); from 5.15, before 5.15.110 (fixed in 5.15.110); from 6.1, before 6.1.27 (fixed in 6.1.27); …
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only

Published 2023-03-27. Last modified 2026-09-18.