Severity
5.3MEDIUMNVD
OSV7.8OSV3.5
EPSS
2.3%
top 15.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 24

Description

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 5.10.46-1+3
Ubuntulinux/linux_kernel< 4.15.0-151.157+2
debiandebian/linux< linux 5.10.46-1 (bookworm)

Also affects: Netbsd 7.1, Debian Linux 9.0

Patches

🔴Vulnerability Details

8
GHSA
GHSA-326j-j9mx-gf84: An issue was discovered in the kernel in NetBSD 72022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2021-07-20
OSV
linux-kvm vulnerabilities2021-06-25
OSV
linux-oem-5.10 vulnerabilities2021-06-23

📋Vendor Advisories

15
CISA ICS
Siemens SCALANCE FragAttacks2022-04-14
Ubuntu
Linux kernel vulnerabilities2022-03-22
Android
CVE-2020-26139: WLAN2021-10-01
CISA ICS
Hitachi ABB Power Grids TropOS2021-08-24
Ubuntu
Linux kernel vulnerabilities2021-07-20

💬Community

1
HackerOne
Fragmentation and Aggregation Flaws in Wi-Fi2021-07-23
CVE-2020-26139 — Improper Authentication in Netbsd | cvebase