{"id":"DEBIAN-CVE-2023-54286","details":"In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace  A received TKIP key may be up to 32 bytes because it may contain MIC rx/tx keys too. These are not used by iwl and copying these over overflows the iwl_keyinfo.key field.  Add a check to not copy more data to iwl_keyinfo.key then will fit.  This fixes backtraces like this one:   memcpy: detected field-spanning write (size 32) of single field \"sta_cmd.key.key\" at drivers/net/wireless/intel/iwlwifi/dvm/sta.c:1103 (size 16)  WARNING: CPU: 1 PID: 946 at drivers/net/wireless/intel/iwlwifi/dvm/sta.c:1103 iwlagn_send_sta_key+0x375/0x390 [iwldvm]  \u003csnip\u003e  Hardware name: Dell Inc. Latitude E6430/0H3MT5, BIOS A21 05/08/2017  RIP: 0010:iwlagn_send_sta_key+0x375/0x390 [iwldvm]  \u003csnip\u003e  Call Trace:   \u003cTASK\u003e   iwl_set_dynamic_key+0x1f0/0x220 [iwldvm]   iwlagn_mac_set_key+0x1e4/0x280 [iwldvm]   drv_set_key+0xa4/0x1b0 [mac80211]   ieee80211_key_enable_hw_accel+0xa8/0x2d0 [mac80211]   ieee80211_key_replace+0x22d/0x8e0 [mac80211]  \u003csnip\u003e","modified":"2026-09-15T09:02:57.197053054Z","published":"2025-12-30T13:16:17.620Z","upstream":["CVE-2023-54286"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54286"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.37-1"}]}],"versions":["6.1.27-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54286.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54286.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54286.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}