First published: Tue May 11 2021(Updated: )
A flaw was found in ieee80211_rx_h_defragment in net/mac80211/rx.c in the Linux Kernel's WiFi implementation. This vulnerability can be abused to inject packets or exfiltrate selected fragments when another device sends fragmented frames, and the WEP, CCMP, or GCMP data-confidentiality protocol is used. The highest threat from this vulnerability is to integrity.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-348.rt7.130.el8 | 0:4.18.0-348.rt7.130.el8 |
redhat/kernel | <0:4.18.0-348.el8 | 0:4.18.0-348.el8 |
redhat/Kernel | <5.13 | 5.13 |
Linux Linux kernel | >=4.4<4.4.271 | |
Linux Linux kernel | >=4.9<4.9.271 | |
Linux Linux kernel | >=4.14<4.14.235 | |
Linux Linux kernel | >=4.19<4.19.193 | |
Linux Linux kernel | >=5.4<5.4.124 | |
Linux Linux kernel | >=5.10<5.10.42 | |
Linux Linux kernel | >=5.12<5.12.9 | |
Debian Debian Linux | =9.0 | |
All of | ||
Arista C-75 Firmware | ||
Arista C-75 | ||
All of | ||
Arista O-90 Firmware | ||
Arista O-90 | ||
All of | ||
Arista C-65 Firmware | ||
Arista C-65 | ||
All of | ||
Arista W-68 Firmware | ||
Arista W-68 | ||
All of | ||
Siemens Scalance W700 Ieee 802.11n Firmware | ||
Siemens SCALANCE W700 IEEE 802.11n | ||
All of | ||
Siemens Scalance W1700 Ieee 802.11ac Firmware | ||
Siemens Scalance W1700 Ieee 802.11ac | ||
Arista C-75 Firmware | ||
Arista C-75 | ||
Arista O-90 Firmware | ||
Arista O-90 | ||
Arista C-65 Firmware | ||
Arista C-65 | ||
Arista W-68 Firmware | ||
Arista W-68 | ||
Siemens Scalance W700 Ieee 802.11n Firmware | ||
Siemens SCALANCE W700 IEEE 802.11n | ||
Siemens Scalance W1700 Ieee 802.11ac Firmware | ||
Siemens Scalance W1700 Ieee 802.11ac | ||
Google Android | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.112-1 6.11.5-1 6.11.7-1 |
Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.