<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:22:23 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-52531 — wifi: iwlwifi: mvm: Fix a memory corruption issue</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-52531</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: iwlwifi: mvm: Fix a memory corruption issue&lt;/p&gt;
&lt;p&gt;A few lines above, space is kzalloc()&amp;#39;ed for:
	sizeof(struct iwl_nvm_data) +
	sizeof(struct ieee80211_channel) +
	sizeof(struct ieee80211_rate)&lt;/p&gt;
&lt;p&gt;&amp;#39;mvm-&amp;gt;nvm_data&amp;#39; is a &amp;#39;struct iwl_nvm_data&amp;#39;, so it is fine.&lt;/p&gt;
&lt;p&gt;At the end of this structure, there is the &amp;#39;channels&amp;#39; flex array.
Each element is of type &amp;#39;struct ieee80211_channel&amp;#39;.
So only 1 element is allocated in this array.&lt;/p&gt;
&lt;p&gt;When doing:
  mvm-&amp;gt;nvm_data-&amp;gt;bands[0].channels = mvm-&amp;gt;nvm_data-&amp;gt;channels;
We point at the first element of the &amp;#39;channels&amp;#39; flex array.
So this is fine.&lt;/p&gt;
&lt;p&gt;However, when doing:
  mvm-&amp;gt;nvm_data-&amp;gt;bands[0].bitrates =
			(void *)((u8 *)mvm-&amp;gt;nvm_data-&amp;gt;channels + 1);
because of the &amp;#34;(u8 *)&amp;#34; cast, we add only 1 to the address of the beginning
of the flex array.&lt;/p&gt;
&lt;p&gt;It is likely that we want point at the &amp;#39;struct ieee80211_rate&amp;#39; allocated
just after.&lt;/p&gt;
&lt;p&gt;Remove the spurious casting so that the pointer arithmetic works as
expected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: iwlwifi: mvm: Fix a memory corruption issue&lt;/p&gt;
&lt;p&gt;A few lines above, space is kzalloc()&amp;#39;ed for:
	sizeof(struct iwl_nvm_data) +
	sizeof(struct ieee80211_channel) +
	sizeof(struct ieee80211_rate)&lt;/p&gt;
&lt;p&gt;&amp;#39;mvm-&amp;gt;nvm_data&amp;#39; is a &amp;#39;struct iwl_nvm_data&amp;#39;, so it is fine.&lt;/p&gt;
&lt;p&gt;At the end of this structure, there is the &amp;#39;channels&amp;#39; flex array.
Each element is of type &amp;#39;struct ieee80211_channel&amp;#39;.
So only 1 element is allocated in this array.&lt;/p&gt;
&lt;p&gt;When doing:
  mvm-&amp;gt;nvm_data-&amp;gt;bands[0].channels = mvm-&amp;gt;nvm_data-&amp;gt;channels;
We point at the first element of the &amp;#39;channels&amp;#39; flex array.
So this is fine.&lt;/p&gt;
&lt;p&gt;However, when doing:
  mvm-&amp;gt;nvm_data-&amp;gt;bands[0].bitrates =
			(void *)((u8 *)mvm-&amp;gt;nvm_data-&amp;gt;channels + 1);
because of the &amp;#34;(u8 *)&amp;#34; cast, we add only 1 to the address of the beginning
of the flex array.&lt;/p&gt;
&lt;p&gt;It is likely that we want point at the &amp;#39;struct ieee80211_rate&amp;#39; allocated
just after.&lt;/p&gt;
&lt;p&gt;Remove the spurious casting so that the pointer arithmetic works as
expected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-52531</guid>
    </item>
  </channel>
</rss>
