CVE-2020-26141

Related Vulnerabilities: CVE-2020-26141  

A vulnerability was found in Linux kernel's WiFi implementation. An attacker within wireless range can inject a control packet fragment where the kernel does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames.

Description

A vulnerability was found in Linux kernel's WiFi implementation. An attacker within wireless range can inject a control packet fragment where the kernel does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames.

Mitigation

Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Additional Information

  • Bugzilla 1960492: CVE-2020-26141 kernel: not verifying TKIP MIC of fragmented frames
  • CWE-346->CWE-863: Origin Validation Error leads to Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2020-26141