QID 375413

QID 375413: IBM Security Guardium kernel Vulnerability (6152439)

Guardium is a comprehensive data protection platform that enables security teams to automatically analyze sensitive-data environments such as databases, data warehouses, big data platforms, cloud environments, file systems, mainframes.


CVE-2019-3846: Linux Kernel is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the mwifiex_update_bss_desc_with_ie function in drivers/net/wireless/marvell/mwifiex/scan.c. By sending specially-crafted beacon packets

Affected Version:
IBM Security Guardium 10.5
IBM Security Guardium 10.6
IBM Security Guardium 11.0
IBM Security Guardium 11.1

QID Detection Logic(Authenticated):
This qid will check the vulnerable version of installed IBM Security Guardium

A remote attacker could overflow a buffer and execute arbitrary code or cause a denial of service condition on the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    Vendor has issued fix to this vulnerability. Refer to IBM advisory 6152439 to address this issue and obtain further details.
    Vendor References

    CVEs related to QID 375413

    Software Advisories
    Advisory ID Software Component Link
    6152439 Linux URL Logo www.ibm.com/support/pages/node/6152439