Description: Heap Overflow in mwifiex_update_vs_ie() function References: https://www.openwall.com/lists/oss-security/2019/08/28/1 https://lore.kernel.org/linux-wireless/20190828020751.13625-1-huangwenabc@gmail.com/ Notes: bwh> Introduced in 3.6 by commit 2152fe9c2fa4 "mwifiex: parse WPS IEs from bwh> beacon_data". Bugs: upstream: released (5.3) [7caac62ed598a196d6ddf8d9c121e12e082cac3a] 4.19-upstream-stable: released (4.19.75) [941431c491a68e0428bdfb46bbe4cbc52f7bfabb] 4.9-upstream-stable: released (4.9.194) [21dfacaf201ed13af70a8bd3e66bcf18cdb63b35] 3.16-upstream-stable: released (3.16.74) [fb8186b15518423646f0e2105c34b3e620623b4e] sid: released (5.2.17-1) 4.19-buster-security: released (4.19.87-1) 4.9-stretch-security: released (4.9.210-1) 3.16-jessie-security: released (3.16.74-1)