Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8 MGASA-2021-0104 Moderate Threat: Broadcom Info Leak

mageia
Calendar Grey March 4, 2021
Dist Mageia Esm H88
Recent modifications to nonfree firmware packages address security vulnerabilities on Broadcom devices, improving hardware compatibility and safeguarding functionalities.
Updated nonfree firmwares fixees various issues, adds new / improved hardware support and fixes atleast the following security issue: An issue was discovered on Broadcom Wi-Fi cli...

Summary

Updated nonfree firmwares fixees various issues, adds new / improved hardware support and fixes atleast the following security issue:
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic (CVE-2019-15126).
Full list of updates: * kernel-firmware-nonfree: - add firmware for Lontium LT9611UXC DSI to HDMI bridge - brcm: Add NVRAM for Vamrs 96boards Rock960 - brcm: make AP6212 in bananpi m2 plus/zero work - brcm: Link RPi4's WiFi firmware with DMI machine name - brcm: Update Raspberry Pi 3B+/4B NVRAM for downstream changes - brcm: remove old brcm firmwares that have newer cypress variants (CVE-2019-15126) - cypress: Link the new cypress firmware to the old brcm files (CVE-2019-15126) - i915: Add GuC f...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=28500

- https://www.cve.org/CVERecord?id=CVE-2019-15126

Resolution

SRPMS

- 8/nonfree/kernel-firmware-nonfree-20210223-1.mga8.nonfree

Publication date: 04 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0104.html
Type: security
CVE: CVE-2019-15126

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here