8827Ì«Ñô¼¯ÍÅADLab£º²©Í¨Wi-FiÇý¶¯¶à¸ö°²È«·ì϶ÖÒ¸æ

°ä²¼¹¦·ò 2019-04-21

²©Í¨ÊÇÈ«ÇòÎÞÏßÉ豸µÄÖØÒª¹©¸øÉÌÖ®Ò»£¬£¬£¬ £¬£¬£¬²©Í¨µÄ43ϵÁеÄwifiоƬ±»¿í·ºÀûÓÃÓÚÖÇÄÜÊÖ»ú¡¢±Ê¼Ç±¾µçÄÔ¡¢ÖÇÄܵçÊÓºÍÎïÁªÍøÉ豸¡£¡£¡£¡£¡£¡£¡£¡£½üÈÕ£¬£¬£¬ £¬£¬£¬US-CERT°ä²¼Á˶à¸ö²©Í¨wi-FiоƬÇý¶¯µÄ°²È«Ô¤¾¯£¨CVE-2019-9500¡¢CVE-2019-9501¡¢CVE-2019-9502¡¢CVE-2019-9503£©¡£¡£¡£¡£¡£¡£¡£¡£


ÕâËĸö·ì϶±ðÀëÊDz©Í¨wlÇý¶¯ÖеÄÁ½¸ö¶ÑÒç¶Âí½Å£¨CVE-2019-9501¡¢CVE-2019-9502£©£¬£¬£¬ £¬£¬£¬¿ªÔ´µÄbrcmfmacÇý¶¯ÖеÄÊý¾ÝÖ¡ÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-9503£©¼°¶ÑÒç¶Âí½Å(CVE-2019-9500£©¡£¡£¡£¡£¡£¡£¡£¡£Î´¾­ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü£¬£¬£¬ £¬£¬£¬ÔÚ×îÑϳÁµÄÇé¿öÏ£¬£¬£¬ £¬£¬£¬Äܹ»ÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ·ì϶ÀûÓÃǰÌáµÄÊÜÏÞ£¬£¬£¬ £¬£¬£¬Í¨³£Çé¿öÏ£¬£¬£¬ £¬£¬£¬ÕâЩ·ì϶Äܹ»Ôì³É»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£



²©Í¨Ð¾Æ¬Çý¶¯¼ò½é


²©Í¨WIFIоƬ43xxxÇý¶¯·¨Ê½¼¯·ÖΪ¿ªÔ´ºÍרÓÐÁ½Àà¡£¡£¡£¡£¡£¡£¡£¡£


¿ªÔ´

b43£¨Linux£©

brcmsmac£¨SoftMAC / Linux£©

brcmfmac£¨FullMAC / Linux£©

bcmdhd£¨FullMAC /  Android£©

רÓÐ

broadcom-sta(wl) ( SoftMAC  && FullMAC / Linux)


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ1 ²©Í¨Ð¾Æ¬Çý¶¯¼°ÀûÓÃϵͳ



·ì϶·ÖÎö


brcmfmacÇý¶¯Á½¸ö·ì϶£¨CVE-2019-9503¡¢CVE-2019-9500£©


²©Í¨Wi-FiоƬÓëÖ÷»úµÄÊäÈëÊä³ö½Ó¿ÚѡȡUSB£¬£¬£¬ £¬£¬£¬SDIOºÍPCIeÈýÖÖBus×ÜÏß·½Ê½¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÈí¼þ²ãÃæ£¬£¬£¬ £¬£¬£¬Çý¶¯ºÍÖ÷»úµÄÊý¾ÝͨѶÓÐÁ½ÖÖ·½Ê½£¬£¬£¬ £¬£¬£¬Ò»ÖÖÊÇIOCTRL£¬£¬£¬ £¬£¬£¬Ò»ÖÖÊÇEventÊÂÎñ֪ͨ¡£¡£¡£¡£¡£¡£¡£¡£Wi-FiоƬʹÓù̼þÊÂÎñÀ´Í¨ÖªÖ÷»ú·ÖÆçµÄÊÂÎñ£ºÉ¨ÃèÁ˾֡¢¹ØÁª/½â³ý¹ØÁª¡¢Éí·ÝÑéÖ¤µÈ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-9503


µ±brcmfmacÇý¶¯´ÓÔ¶¶ËÆðÔ´½Ó¹Üµ½Ò»¸ö¹Ì¼þÊÂÎñÊý¾Ý֡ʱ£¬£¬£¬ £¬£¬£¬is_wlc_event_frameº¯Êý½«±»Å²Ó㬣¬£¬ £¬£¬£¬¸Ãº¯ÊýÓÃÓÚÅжÏEventµÄÊý¾ÝÖ¡¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÇý¶¯´ÓHost²à½ÓÊܵ½¸Ã¹Ì¼þÊÂÎñÊý¾Ý֡ʱ£¬£¬£¬ £¬£¬£¬½«»á´¥·¢¸ÃÅжϻúÔì¡£¡£¡£¡£¡£¡£¡£¡£¸Ãº¯Êý´æÔÚ·ì϶£¬£¬£¬ £¬£¬£¬Ê¹Çе±Ê¹ÓÃUSBµÄBUS½Ó¿Ú£¨Èç±íÖÃUSB wifiÍø¿¨£©Ê±£¬£¬£¬ £¬£¬£¬Í¨¹ý»ú¹Øbcm_hdr.subtype>=0£¬£¬£¬ £¬£¬£¬¸ÃÅжϻúÔìÄܹ»±»Èƹý£¬£¬£¬ £¬£¬£¬´Ó¶øÔì³ÉÔ¶¶ËÆðÔ´µÄ·¸·¨Êý¾ÝÖ¡Äܹ»±»ºóÐøÁ÷³Ì´¦Öᣡ£¡£¡£¡£¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ2 is_wlc_event_frameº¯ÊýÎÊÌâʾÒâ


CVE-2019-9500


brcmf_wowl_nd_resultsº¯Êý´æÔÚ¶ÑÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇWLANÅäÖÃÁË»½ÐÑÖ°ÄÜ£¬£¬£¬ £¬£¬£¬¸Ãº¯Êý½«±»ÓÃÓÚ³Á×éÊÂÎñÊý¾ÝÖ¡¡£¡£¡£¡£¡£¡£¡£¡£µ±Çý¶¯ÊÕµ½Ò»¸ö¶ñÒâ»ú¹ØµÄÊÂÎñÊý¾Ý֡ʱ£¬£¬£¬ £¬£¬£¬½«»á´¥·¢¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£¡£802.11ºÍ̸»®¶¨eSSID×ֶβ»ÄÜ´óÓÚ32×Ö½Ú£¬£¬£¬ £¬£¬£¬µ±¹¥»÷Õßͨ¹ýÔ¶³Ì´¥·¢¹Ì¼þÊÂÎñ£¬£¬£¬ £¬£¬£¬ÊÂÎñÖ¡ÖеÄSSIDµÄ³¤¶È´óÓÚ32×Ö½Úʱ£¬£¬£¬ £¬£¬£¬½«»á´¥·¢¶ÑÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3 brcmf_wowl_nd_resultsº¯ÊýÎÊÌâʾÒâ


²©Í¨wlÇý¶¯ÖÐÁ½¸ö·ì϶£¨CVE-2019-9501¡¢ CVE-2019-9502£©


CVE-2019-9501¼° CVE-2019-9502ÊDz©Í¨wlÇý¶¯ÖÐÁ½¸ö¶ÑÒç¶Âí½Å£¬£¬£¬ £¬£¬£¬µ±É豸½Ó¼ûAPÈȵãʱ£¬£¬£¬ £¬£¬£¬ÔÚËÄ´ÎÎÕÊÖ½»»¥¹ý³ÌÖеĵÚÈý²½£¬£¬£¬ £¬£¬£¬ÔÚÇý¶¯·ÖÎöEAPOLÐÂÎÅʱ£¬£¬£¬ £¬£¬£¬½«»á´¥·¢ÕâÁ½¸ö¶ÑÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4 wlÇý¶¯·ì϶ʾÒâͼ


CVE-2019-9501


APÏòStation·¢Ë͵ÄEAPOL M3ÐÂÎÅÖУ¬£¬£¬ £¬£¬£¬ÈôÊÇvendor information×ֶγ¤¶È´óÓÚ32×Ö½Úʱ£¬£¬£¬ £¬£¬£¬½«»áÔÚwlc_wpa_sup_eapolº¯Êý´¥·¢¶ÑÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-9502


APÏòStation·¢Ë͵ÄEAPOL M3ÐÂÎÅÖУ¬£¬£¬ £¬£¬£¬ÈôÊÇvendor information ×ֶγ¤¶È´óÓÚ164×Ö½Úʱ£¬£¬£¬ £¬£¬£¬½«»áÔÚwlc_wpa_plumb_gtkº¯Êý´¥·¢¶ÑÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5 wlc_wpa_plumb_gtkº¯ÊýÎÊÌâʾÒâ 


ÊÜÓ°Ïì²úÆ·


²©Í¨¹«Ë¾


²©Í¨¹«Ë¾Ã»ÓÐÌṩÊÜÓ°Ïì²úÆ·ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


Synology¹«Ë¾


Synology¹«Ë¾µÄRT1900ac²úÆ·ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÚRT1900ac²úÆ·ÖÐĬÈϲ»±»´¥·¢£¬£¬£¬ £¬£¬£¬µ±²úÆ·Äܹ»ÓÉÖÎÀíÔ±ÅäÖÃÆôÓÃijÏîÅäÖÃʱ£¬£¬£¬ £¬£¬£¬²Å»áÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬ £¬£¬£¬Synology¹«Ë¾ÒÔΪRT1900acÖи÷ì϶Óп϶¨µÄ¾ÖÏÞÐÔ£¬£¬£¬ £¬£¬£¬Ö»ÓÐÔÚÌØ¶¨µÄÇé¿öÏÂÄÜÁ¦´¥·¢¡£¡£¡£¡£¡£¡£¡£¡£


Apple¹«Ë¾


Apple¹«Ë¾µÄmacOS Sierra 10.12.6¡¢macOS High Sierra 10.13.6¡¢ macOS Mojave 10.14.3²úÆ·ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£


½â¾ö¹æ»®


Apple¹«Ë¾µÄbrcmfmacÇý¶¯µÄ·ì϶Òѽ¨¸´£¬£¬£¬ £¬£¬£¬Óû§Äܹ»¸üÐÂÓйصIJ¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ÊµÏÖ½¨¸´¹¤×÷¡£¡£¡£¡£¡£¡£¡£¡£
²©Í¨¹«Ë¾½¨¸´ÁËLinuxÄÚºËbrcmfmacÇý¶¯ÖеÄCVE-2019-9503¼°CVE-2019-9500Á½¸ö·ì϶£¬£¬£¬ £¬£¬£¬Óû§Äܹ»¸üÐÂÓйصIJ¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ÊµÏÖ½¨¸´¹¤×÷¡£¡£¡£¡£¡£¡£¡£¡£
ʹÓÿÉÐŵÄWI-FIÍøÂ磬£¬£¬ £¬£¬£¬³ö¸ñÊDz»ÒªÔÚ¹«¹²³¡ËùÏνӲ»°²È«µÄwifiÈȵã¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó



1.https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
2.https://kb.cert.org/vuls/id/166939/
3.https://support.apple.com/en-us/HT209600
4.https://www.synology.cn/zh-cn/security/advisory/Synology_SA_19_18
5.https://git.kernel.org/linus/a4176ec356c73a46c07c181c6d04039fafa34a9f
6.https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff