CVE-2023-38417
Publication date 16 May 2024
Last updated 2 October 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| linux-firmware | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Vulnerable, fix deferred
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Notes
rodrigo-zaiden
while it is not clear in the advisory, the understanding is that this is a firmware update on the linux-firmware package, which is what being tracked here. I couldn't find which commit on upstream linux-firmware fixes this issue based on the advisory information only.
gianz
noble: the GA 6.8 kernel loads some blobs from before the fix, and no linux-firmware update can change that. resolute: the Intel WiFi firmware ships in the linux-firmware-intel-wireless source.
Patch details
| Package | Patch details |
|---|---|
| linux-firmware |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.3 · Medium
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L