imPC@ndo IT

Tracker / CVE-2020-26147

CVE-2020-26147

Medium 5.4

An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.

Affected products and versions

arista c-65_firmware
arista c-75_firmware
arista o-90_firmware
arista w-68_firmware
debian debian_linux
linux linux_kernel · 4.14 → 4.14.235
linux linux_kernel · 4.19 → 4.19.193
linux linux_kernel · 4.4 → 4.4.271
linux linux_kernel · 4.9 → 4.9.271
linux linux_kernel · 5.10 → 5.10.42
linux linux_kernel · 5.12 → 5.12.9
linux linux_kernel · 5.4 → 5.4.124
siemens scalance_w1700_ieee_802.11ac_firmware
siemens scalance_w700_ieee_802.11n_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References