CVE-2020-24587: Low severity Google Android vulnerability
Published May 11, 2021
·
Updated
A flaw was found in the Linux kernel's wifi implementation wherein an attacker within wireless range is able to abuse a logic flaw in the wifi implementation by reassembling packets from multiple fragments under different keys and they would be treated as valid. This allows an attacker to send a fragment under an incorrect key and be treated as a valid fragment under the new key.
A flaw was found in the Linux kernel's WiFi implementation. An attacker within the wireless range can abuse a logic flaw in the WiFi implementation by reassembling packets from multiple fragments under different keys, treating them as valid. This flaw allows an attacker to send a fragment under an incorrect key, treating them as a valid fragment under the new key. The highest threat from this vulnerability is to confidentiality.
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Event History
May 11, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Oct 4, 2021
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·04:22 AM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
CVE-2020-24587 has been rated as high severity, indicating a significant potential impact on system security.
2
How do I fix CVE-2020-24587?
To remediate CVE-2020-24587, update the Linux kernel to the recommended versions provided by your distribution, specifically 0:4.18.0-348.el8 or later.
3
Who is affected by CVE-2020-24587?
CVE-2020-24587 affects systems running specific versions of the Linux kernel, as well as certain firmware for wireless devices.
4
Is CVE-2020-24587 exploitability confirmed?
Yes, CVE-2020-24587 is confirmed to be exploitable by attackers within wireless range, leading to potential unauthorized access.
5
What types of devices are vulnerable to CVE-2020-24587?
Devices vulnerable to CVE-2020-24587 primarily include those utilizing affected versions of the Linux kernel and specific wireless firmware.
SecAlerts Pty Ltd. 132 Wickham Terrace Fortitude Valley, QLD 4006, Australia info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.