CVE-2020-26146: Input Validation
A vulnerability was found in Linux kernel, where the WiFi implementation reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Other sources
A vulnerability was found in Linux Kernel, where the wifi implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
upstream patch: https://lore.kernel.org/linux-wireless/20210511180259.159598-1-johannes@sipsolutions.net/
— Red Hat
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-26146.
What is the severity of CVE-2020-26146?
The severity of CVE-2020-26146 is high with a severity value of 5.3.
Which devices are affected by CVE-2020-26146?
The Samsung Galaxy S3 i9305 with firmware version 4.4.4 is affected by CVE-2020-26146.
How can an adversary exploit this vulnerability?
An adversary can exploit CVE-2020-26146 by abusing the WiFi implementation to exfiltrate selected fragments.
Where can I find more information about CVE-2020-26146?
You can find more information about CVE-2020-26146 on the following references: [Reference 1](https://lore.kernel.org/linux-wireless/20210511180259.159598-1-johannes@sipsolutions.net/), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1960503), [Reference 3](https://access.redhat.com/errata/RHSA-2021:4140)