¼øºÚµ£±£ÍøADLab£º²©Í¨Wi-FiÇý¶¯¶à¸öÇå¾²Îó²îÖÒÑÔ

Ðû²¼Ê±¼ä 2019-04-21

²©Í¨ÊÇÈ«ÇòÎÞÏß×°±¸µÄÖ÷Òª¹©Ó¦ÉÌÖ®Ò» £¬ £¬£¬£¬£¬£¬£¬²©Í¨µÄ43ϵÁеÄwifiоƬ±»ÆÕ±éÓ¦ÓÃÓÚÖÇÄÜÊÖ»ú¡¢Ìõ¼Ç±¾µçÄÔ¡¢ÖÇÄܵçÊÓºÍÎïÁªÍø×°±¸¡£¡£¡£¡£¡£¡£¿ËÈÕ £¬ £¬£¬£¬£¬£¬£¬US-CERTÐû²¼Á˶à¸ö²©Í¨wi-FiоƬÇý¶¯µÄÇå¾²Ô¤¾¯£¨CVE-2019-9500¡¢CVE-2019-9501¡¢CVE-2019-9502¡¢CVE-2019-9503£©¡£¡£¡£¡£¡£¡£


ÕâËĸöÎó²î»®·ÖÊDz©Í¨wlÇý¶¯ÖеÄÁ½¸ö¶ÑÒç³öÎó²î£¨CVE-2019-9501¡¢CVE-2019-9502£© £¬ £¬£¬£¬£¬£¬£¬¿ªÔ´µÄbrcmfmacÇý¶¯ÖеÄÊý¾ÝÖ¡ÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2019-9503£©¼°¶ÑÒç³öÎó²î(CVE-2019-9500£©¡£¡£¡£¡£¡£¡£Î´¾­ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü £¬ £¬£¬£¬£¬£¬£¬ÔÚ×îÑÏÖØµÄÇéÐÎÏ £¬ £¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²îʹÓÃÌõ¼þµÄÊÜÏÞ £¬ £¬£¬£¬£¬£¬£¬Í¨³£ÇéÐÎÏ £¬ £¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÒÔÔì³É¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£



²©Í¨Ð¾Æ¬Çý¶¯¼ò½é


²©Í¨WIFIоƬ43xxxÇý¶¯³ÌÐò¼¯·ÖΪ¿ªÔ´ºÍרÓÐÁ½Àà¡£¡£¡£¡£¡£¡£


¿ªÔ´

b43£¨Linux£©

brcmsmac£¨SoftMAC / Linux£©

brcmfmac£¨FullMAC / Linux£©

bcmdhd£¨FullMAC /  Android£©

רÓÐ

broadcom-sta(wl) ( SoftMAC  && FullMAC / Linux)


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ1 ²©Í¨Ð¾Æ¬Çý¶¯¼°Ó¦ÓÃϵͳ



Îó²îÆÊÎö


brcmfmacÇý¶¯Á½¸öÎó²î£¨CVE-2019-9503¡¢CVE-2019-9500£©


²©Í¨Wi-FiоƬÓëÖ÷»úµÄÊäÈëÊä³ö½Ó¿Ú½ÓÄÉUSB £¬ £¬£¬£¬£¬£¬£¬SDIOºÍPCIeÈýÖÖBus×ÜÏß·½·¨¡£¡£¡£¡£¡£¡£ÔÚÈí¼þ²ãÃæ £¬ £¬£¬£¬£¬£¬£¬Çý¶¯ºÍÖ÷»úµÄÊý¾ÝͨѶÓÐÁ½ÖÖ·½·¨ £¬ £¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇIOCTRL £¬ £¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇEventÊÂÎñ֪ͨ¡£¡£¡£¡£¡£¡£Wi-FiоƬʹÓù̼þÊÂÎñÀ´Í¨ÖªÖ÷»ú²î±ðµÄÊÂÎñ£ºÉ¨ÃèЧ¹û¡¢¹ØÁª/ɨ³ý¹ØÁª¡¢Éí·ÝÑéÖ¤µÈ¡£¡£¡£¡£¡£¡£


CVE-2019-9503


µ±brcmfmacÇý¶¯´ÓÔ¶¶ËȪԴÎüÊÕµ½Ò»¸ö¹Ì¼þÊÂÎñÊý¾Ý֡ʱ £¬ £¬£¬£¬£¬£¬£¬is_wlc_event_frameº¯Êý½«±»Å²Óà £¬ £¬£¬£¬£¬£¬£¬¸Ãº¯ÊýÓÃÓÚÅжÏEventµÄÊý¾ÝÖ¡¡£¡£¡£¡£¡£¡£ÈôÊÇÇý¶¯´ÓHost²à½ÓÊܵ½¸Ã¹Ì¼þÊÂÎñÊý¾Ý֡ʱ £¬ £¬£¬£¬£¬£¬£¬½«»á´¥·¢¸ÃÅжϻúÖÆ¡£¡£¡£¡£¡£¡£¸Ãº¯Êý±£´æÎó²î £¬ £¬£¬£¬£¬£¬£¬Ê¹Êʵ±Ê¹ÓÃUSBµÄBUS½Ó¿Ú£¨ÈçÍâÖÃUSB wifiÍø¿¨£©Ê± £¬ £¬£¬£¬£¬£¬£¬Í¨¹ý½á¹¹bcm_hdr.subtype>=0 £¬ £¬£¬£¬£¬£¬£¬¸ÃÅжϻúÖÆ¿ÉÒÔ±»Èƹý £¬ £¬£¬£¬£¬£¬£¬´Ó¶øÔì³ÉÔ¶¶ËȪԴµÄ²»·¨Êý¾ÝÖ¡¿ÉÒÔ±»ºóÐøÁ÷³Ì´¦Öóͷ£¡£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ2 is_wlc_event_frameº¯ÊýÎÊÌâʾÒâ


CVE-2019-9500


brcmf_wowl_nd_resultsº¯Êý±£´æ¶ÑÒç³öÎó²î¡£¡£¡£¡£¡£¡£ÈôÊÇWLANÉèÖÃÁ˽ÐÐѹ¦Ð§ £¬ £¬£¬£¬£¬£¬£¬¸Ãº¯Êý½«±»ÓÃÓÚÖØ×éÊÂÎñÊý¾ÝÖ¡¡£¡£¡£¡£¡£¡£µ±Çý¶¯ÊÕµ½Ò»¸ö¶ñÒâ½á¹¹µÄÊÂÎñÊý¾Ý֡ʱ £¬ £¬£¬£¬£¬£¬£¬½«»á´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£¡£802.11ЭÒé»®¶¨eSSID×ֶβ»¿É´óÓÚ32×Ö½Ú £¬ £¬£¬£¬£¬£¬£¬µ±¹¥»÷Õßͨ¹ýÔ¶³Ì´¥·¢¹Ì¼þÊÂÎñ £¬ £¬£¬£¬£¬£¬£¬ÊÂÎñÖ¡ÖеÄSSIDµÄ³¤¶È´óÓÚ32×Ö½Úʱ £¬ £¬£¬£¬£¬£¬£¬½«»á´¥·¢¶ÑÒç³öÎó²î¡£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ3 brcmf_wowl_nd_resultsº¯ÊýÎÊÌâʾÒâ


²©Í¨wlÇý¶¯ÖÐÁ½¸öÎó²î£¨CVE-2019-9501¡¢ CVE-2019-9502£©


CVE-2019-9501¼° CVE-2019-9502ÊDz©Í¨wlÇý¶¯ÖÐÁ½¸ö¶ÑÒç³öÎó²î £¬ £¬£¬£¬£¬£¬£¬µ±×°±¸»á¼ûAPÈÈÃÅʱ £¬ £¬£¬£¬£¬£¬£¬ÔÚËÄ´ÎÎÕÊÖ½»»¥Àú³ÌÖеĵÚÈý²½ £¬ £¬£¬£¬£¬£¬£¬ÔÚÇý¶¯ÆÊÎöEAPOLÐÂÎÅʱ £¬ £¬£¬£¬£¬£¬£¬½«»á´¥·¢ÕâÁ½¸ö¶ÑÒç³öÎó²î¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ4 wlÇý¶¯Îó²îʾÒâͼ


CVE-2019-9501


APÏòStation·¢Ë͵ÄEAPOL M3ÐÂÎÅÖÐ £¬ £¬£¬£¬£¬£¬£¬ÈôÊÇvendor information×ֶγ¤¶È´óÓÚ32×Ö½Úʱ £¬ £¬£¬£¬£¬£¬£¬½«»áÔÚwlc_wpa_sup_eapolº¯Êý´¥·¢¶ÑÒç³öÎó²î¡£¡£¡£¡£¡£¡£


CVE-2019-9502


APÏòStation·¢Ë͵ÄEAPOL M3ÐÂÎÅÖÐ £¬ £¬£¬£¬£¬£¬£¬ÈôÊÇvendor information ×ֶγ¤¶È´óÓÚ164×Ö½Úʱ £¬ £¬£¬£¬£¬£¬£¬½«»áÔÚwlc_wpa_plumb_gtkº¯Êý´¥·¢¶ÑÒç³öÎó²î¡£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ5 wlc_wpa_plumb_gtkº¯ÊýÎÊÌâʾÒâ 


ÊÜÓ°Ïì²úÆ·


²©Í¨¹«Ë¾


²©Í¨¹«Ë¾Ã»ÓÐÌṩÊÜÓ°Ïì²úÆ·ÐÅÏ¢¡£¡£¡£¡£¡£¡£


Synology¹«Ë¾


Synology¹«Ë¾µÄRT1900ac²úÆ·ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÚRT1900ac²úÆ·ÖÉñ¬Èϲ»±»´¥·¢ £¬ £¬£¬£¬£¬£¬£¬µ±²úÆ·¿ÉÒÔÓÉÖÎÀíÔ±ÉèÖÃÆôÓÃijÏîÉèÖÃʱ £¬ £¬£¬£¬£¬£¬£¬²Å»áÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£Òò´Ë £¬ £¬£¬£¬£¬£¬£¬Synology¹«Ë¾ÒÔΪRT1900acÖиÃÎó²îÓÐÒ»¶¨µÄ¾ÖÏÞÐÔ £¬ £¬£¬£¬£¬£¬£¬Ö»ÓÐÔÚÌØ¶¨µÄÇéÐÎÏ²Żª´¥·¢¡£¡£¡£¡£¡£¡£


Apple¹«Ë¾


Apple¹«Ë¾µÄmacOS Sierra 10.12.6¡¢macOS High Sierra 10.13.6¡¢ macOS Mojave 10.14.3²úÆ·ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£


½â¾ö¼Æ»®


Apple¹«Ë¾µÄbrcmfmacÇý¶¯µÄÎó²îÒÑÐÞ¸´ £¬ £¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ¸üÐÂÏà¹ØµÄ²¹¶¡ £¬ £¬£¬£¬£¬£¬£¬Íê³ÉÐÞ¸´ÊÂÇé¡£¡£¡£¡£¡£¡£
²©Í¨¹«Ë¾ÐÞ¸´ÁËLinuxÄÚºËbrcmfmacÇý¶¯ÖеÄCVE-2019-9503¼°CVE-2019-9500Á½¸öÎó²î £¬ £¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ¸üÐÂÏà¹ØµÄ²¹¶¡ £¬ £¬£¬£¬£¬£¬£¬Íê³ÉÐÞ¸´ÊÂÇé¡£¡£¡£¡£¡£¡£
ʹÓÿÉÐŵÄWI-FIÍøÂç £¬ £¬£¬£¬£¬£¬£¬ÌØÊâÊDz»ÒªÔÚ¹«¹²³¡ºÏÅþÁ¬²»Çå¾²µÄwifiÈÈÃÅ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó



1.https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
2.https://kb.cert.org/vuls/id/166939/
3.https://support.apple.com/en-us/HT209600
4.https://www.synology.cn/zh-cn/security/advisory/Synology_SA_19_18
5.https://git.kernel.org/linus/a4176ec356c73a46c07c181c6d04039fafa34a9f
6.https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff