Domain: marvell.com
Stories and comments across the archive that link to marvell.com.
Stories · 2
-
Firmware Vulnerability In Popular Wi-Fi Chipset Affects Laptops, Smartphones, Routers, Gaming Devices (zdnet.com)
Embedi security researcher Denis Selianin has discovered a vulnerability affecting the firmware of a popular Wi-Fi chipset deployed in a wide range of devices, such as laptops, smartphones, gaming rigs, routers, and Internet of Things (IoT) devices. According to Selianin, the vulnerability impacts ThreadX, a real-time operating system that is used as firmware for billions of devices. ZDNet reports: In a report published today, Selianin described how someone could exploit the ThreadX firmware installed on a Marvell Avastar 88W8897 wireless chipset to execute malicious code without any user interaction. The researcher chose this WiFi SoC (system-on-a-chip) because this is one of the most popular WiFi chipsets on the market, being deployed with devices such as Sony PlayStation 4, Xbox One, Microsoft Surface laptops, Samsung Chromebooks, Samsung Galaxy J1 smartphones, and Valve SteamLink cast devices, just to name a few.
"I've managed to identify ~4 total memory corruption issues in some parts of the firmware," said Selianin. "One of the discovered vulnerabilities was a special case of ThreadX block pool overflow. This vulnerability can be triggered without user interaction during the scanning for available networks." The researcher says the firmware function to scan for new WiFi networks launches automatically every five minutes, making exploitation trivial. All an attacker has to do is send malformed WiFi packets to any device with a Marvell Avastar WiFi chipset and wait until the function launches, to execute malicious code and take over the device. Selianin says he also "identified two methods of exploiting this technique, one that is specific to Marvell's own implementation of the ThreadX firmware, and one that is generic and can be applied to any ThreadX-based firmware, which, according to the ThreatX homepage, could impact as much as 6.2 billion devices," the report says. Patches are reportedly being worked on. -
$100 Linux Wall-Wart Now Available
nerdyH sends us to LinuxDevices for a description of a tiny Linux device called the Marvell SheevaPlug. "A $100 Linux wall wart could do to servers what netbooks did to notebooks. With the Marvell SheevaPlug, you get a completely open (hardware and software) Linux server resembling a typical wall-wart power adapter, but running Linux on a 1.2GHz CPU, with 512MB of RAM, and 512MB of Flash. I/O includes USB 2.0, gigabit Ethernet, while expansion is provided via an SDIO slot. The power draw is a nightlight-like 5 Watts. Marvell says it plans to give Linux developers everything they need to deliver 'disruptive' services on the device." The article links four products built on the SheevaPlug, none of them shipping quite yet. The development kit is available from Marvell.