New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 761785 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 762487
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Firmware bug in Broadcom WiFi firmware CVE-2017-11121

Project Member Reported by mnissler@chromium.org, Sep 4 2017

Issue description

There's a vulnerability in Broadcom WiFi firmware, which Broadcom tracks as "V2017061205 / CVE-2017-11121 - fbt buffer overrun in aes keywrap and gtk update".

The bug amounts to remotely-executable buffer overflows in the firmware, potentially allowing the attacker to execute code in the context of the firmware.

Only mitigating factor is that the BCM 4354 parts are hooked up via SDIO with the system so don't have DMA capabilities.

We'll require updated firmware from Broadcom to pick up the fix, which Terry is going to provide.
 
Hi, 

Firmwre release as attachment, which apply security fix "V2017061205 / CVE-2017-11121 - fbt buffer overrun in aes keywrap and gtk update".

Thanks.
Terry
7.81.2_brcmfmac4354-sdio.bin
589 KB Download
Status: Started (was: Assigned)
Firmware in comment #2 working fine in basic testing. CL to pull it in: https://chromium-review.googlesource.com/c/chromium/src/+/641553
I included the wrong CL link in comment #2, apologies. Correct CL is https://chromium-review.googlesource.com/649366
Cc: harpreet@chromium.org rjahagir@chromium.org

Comment 5 by ketakid@google.com, Sep 4 2017

Cc: kirtika@chromium.org snanda@chromium.org
Adding Sameer and Kirtika.
Project Member

Comment 6 by bugdroid1@chromium.org, Sep 5 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromiumos/third_party/linux-firmware/+/5648a83c2dd5e4a98eb52c464992668f8dc6ae7f

commit 5648a83c2dd5e4a98eb52c464992668f8dc6ae7f
Author: Mattias Nissler <mnissler@chromium.org>
Date: Tue Sep 05 20:44:04 2017

Update brcmfmac4354 firmware to version 7.81.2

BUG= chromium:761785 
TEST=WiFi connection successful with new firmware.

Change-Id: I1d6dcf0f72fa65e4176f02c2385ecea599fb05d0
Reviewed-on: https://chromium-review.googlesource.com/649366
Commit-Ready: Mattias Nissler <mnissler@chromium.org>
Tested-by: Mattias Nissler <mnissler@chromium.org>
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>

[modify] https://crrev.com/5648a83c2dd5e4a98eb52c464992668f8dc6ae7f/brcm/brcmfmac4354-sdio.bin

Labels: Merge-Request-62 Merge-Request-61
Status: Fixed (was: Started)
Project Member

Comment 8 by sheriffbot@chromium.org, Sep 5 2017

Labels: -Merge-Request-61 Merge-Review-61 Hotlist-Merge-Review
This bug requires manual review: Request affecting a post-stable build
Please contact the milestone owner if you have questions.
Owners: amineer@(Android), cmasso@(iOS), ketakid@(ChromeOS), govind@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -harpreet@chromium.org bhthompson@chromium.org har@google.com
+Bernie for 62.
Project Member

Comment 10 by sheriffbot@chromium.org, Sep 6 2017

Labels: -M-60 M-61
Project Member

Comment 11 by sheriffbot@chromium.org, Sep 6 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: -Merge-Review-61 -Merge-Request-62 Merge-Approved-62 Merge-Approved-61
Approving merge to M61 and M62.
Note that there's another pending firmware update per  issue 762487 . I'll hold off with the merges for now until we have the final fixed firmware images.
Project Member

Comment 14 by sheriffbot@chromium.org, Sep 11 2017

Cc: keta...@chromium.org
This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible!

If all merges have been completed, please remove any remaining Merge-Approved labels from this issue.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Mergedinto: 762487
Status: Duplicate (was: Fixed)
Duplicating since this is superseded by a subsequent firmware update.
Project Member

Comment 16 by sheriffbot@chromium.org, Sep 15 2017

This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible!

If all merges have been completed, please remove any remaining Merge-Approved labels from this issue.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Merge-Approved-61 -Merge-Approved-62
No merges required, merges for  issue 762487  took care of things.
Project Member

Comment 18 by sheriffbot@chromium.org, Dec 20 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment