CVE-2020-26141
Public on 2021-05-11
Modified on 2022-01-10
Description
A vulnerability was found in Linux kernel's WiFi implementation. An attacker within wireless range can inject a control packet fragment where the kernel does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Kernel-5.10 Extra | kernel | 2022-01-28 | ALAS2KERNEL-5.10-2022-002 | Fixed |
Amazon Linux 2 - Kernel-5.4 Extra | kernel | 2022-01-28 | ALAS2KERNEL-5.4-2022-004 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
NVD | CVSSv2 | 3.3 | AV:A/AC:L/Au:N/C:N/I:P/A:N |