CVE-2021-26676: Medium severity connman vulnerability
Published Feb 9, 2021
·Updated
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
Affected Software
9 affected componentsFixes available
ubuntu/connman<1.36-2.1
1.36-2.1
ubuntu/connman<1.21-1.2+
1.21-1.2+
ubuntu/connman<1.35-6ubuntu0.1~
1.35-6ubuntu0.1~
ubuntu/connman<1.36-2ubuntu0.1
1.36-2ubuntu0.1
debian/connman
1.36-2.1~deb10u21.36-2.1~deb10u51.36-2.2+deb11u21.41-31.42-5
Intel Connman<1.39
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.2
Remediation
Event History
Feb 9, 2021
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:54 PM
Description
Frequently Asked Questions
1
What is CVE-2021-26676?
CVE-2021-26676 is a vulnerability in gdhcp in ConnMan before version 1.39 that could be used by network-adjacent attackers to leak sensitive stack information.
2
How can CVE-2021-26676 be exploited?
CVE-2021-26676 can be exploited by network-adjacent attackers to leak sensitive stack information, which can then be used to further exploit bugs in gdhcp.
3
Which software versions are affected by CVE-2021-26676?
ConnMan versions before 1.39 are affected by CVE-2021-26676.
4
What is the remedy for CVE-2021-26676 in Debian?
For Debian, updating to ConnMan version 1.41-3 or higher will remedy CVE-2021-26676.
5
What is the remedy for CVE-2021-26676 in Ubuntu?
The remedy for CVE-2021-26676 in Ubuntu depends on the specific version. Please refer to the provided references for more information.