CVE-2020-26143

Related Vulnerabilities: CVE-2020-26143  

A vulnerability was found in Linux kernel, where the WiFi implementations assemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.

Description

A vulnerability was found in Linux kernel, where the WiFi implementations assemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.

Additional Information

  • Bugzilla 1960496: CVE-2020-26143 kernel: accepting fragmented plaintext frames in protected networks
  • FAQ: Frequently asked questions about CVE-2020-26143