CVE-2020-24586: Medium severity ieee 802.11 vulnerability
A flaw was found in the Linux kernels implementation of wifi fragmentation handling. An attacker with the ability to transmit within the wireless transmission range of an access point can abuse a flaw where previous contents of wifi fragments can be unintentionally transmitted to another device.
Other sources
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-24586?
CVE-2020-24586 is rated as a medium severity vulnerability.
How do I fix CVE-2020-24586?
To fix CVE-2020-24586, update to the patched versions of the kernel provided by your distribution.
What systems are affected by CVE-2020-24586?
CVE-2020-24586 affects various versions of the Linux kernel, including specific distributions like Red Hat and Debian.
Can CVE-2020-24586 lead to data exposure?
Yes, CVE-2020-24586 can potentially lead to data exposure by unintentionally transmitting previous contents of WiFi fragments.
What is the impact of CVE-2020-24586?
The impact of CVE-2020-24586 allows attackers in proximity to exploit the flaw and intercept data transmissions.