Уязвимость CVE-2020-26147: Информация
Описание
An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.
Важность: MEDIUM (5,4) Вектор: CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N
Опубликовано: 11 мая 2021 г.
Изменено: 12 июля 2022 г.
Исправленные пакеты
Ссылки на рекомендации, решения и инструменты
Ссылка | Ресурс |
---|---|
https://www.fragattacks.com |
|
https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md |
|
[oss-security] 20210511 various 802.11 security issues - fragattacks.com |
|
[debian-lts-announce] 20210623 [SECURITY] [DLA 2690-1] linux-4.19 security update |
|
[debian-lts-announce] 20210623 [SECURITY] [DLA 2689-1] linux security update |
|
https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf |
|
20210511 Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021 |
|
https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 |
|