CVE-2017-9417 firmware fix with b43-fwcutter?

Michael Büsch m at bues.ch
Thu Sep 7 11:54:25 PDT 2017


On Thu, 7 Sep 2017 14:04:55 -0400 (EDT)
Vladis Dronov <vdronov at redhat.com> wrote:

> I would join Drew in asking a question about CVE-2017-9417/Broadpwn.
> My main concern is if this flaw in a firmware above can affect
> laptop/desktop/server Linux systems?
> 
> So far I see two contradicting answers: "he could reproduce the crash
> with the standard Linux firmware [on a mobile phone]" and "I do not
> think that Broadpwm is a problem". Can someone please clarify?


Mobile phones often use FullMAC chips.

That means the chip runs a small operating system and a full 802.11
MLME stack. Usually referred to as "firmware".
This is not to be confused with the "microcode" or "ucode". The ucode
runs on a small sequencer in the 802.11 baseband processor.

FullMAC:	An ARM/MIPS core on the chip runs the 802.11 MLME stack.
		The 802.11 baseband core runs ucode.

SoftMAC:	The host system runs the 802.11 MLME stack.
		The 802.11 baseband core runs ucode.

So if the vulnerability is in the "firmware" and not in the "ucode",
the SoftMAC chips are not affected.

-- 
Michael
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.infradead.org/pipermail/b43-dev/attachments/20170907/79aa4ac6/attachment.sig>


More information about the b43-dev mailing list