CVE-2020-24588

Related Vulnerabilities: CVE-2020-24588  

A flaw was found in the Linux kernels wifi implementation. An attacker within wireless broadcast range can inject custom data into the wireless communication circumventing checks on the data. This can cause the frame to pass checks and be considered a valid frame of a different type.

Description

A flaw was found in the Linux kernels wifi implementation. An attacker within wireless broadcast range can inject custom data into the wireless communication circumventing checks on the data. This can cause the frame to pass checks and be considered a valid frame of a different type.

Mitigation

Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Additional Information

  • Bugzilla 1959657: CVE-2020-24588 kernel: wifi frame payload being parsed incorrectly as an L2 frame
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2020-24588