Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian Buster DSA-4898-1 Critical: wpa Denial Of Service Advisory

debian
Calendar Grey April 22, 2021
Debian Logo
Enhance wpa components to address numerous security concerns, particularly denial of service flaws, on Debian platforms.
Several vulnerabilities have been discovered in wpa_supplicant and hostapd

Summary

CVE-2020-12695

It was discovered that hostapd does not properly handle UPnP
subscribe messages under certain conditions, allowing an attacker to
cause a denial of service.

CVE-2021-0326

It was discovered that wpa_supplicant does not properly process P2P
(Wi-Fi Direct) group information from active group owners. An
attacker within radio range of the device running P2P could take
advantage of this flaw to cause a denial of service or potentially
execute arbitrary code.

CVE-2021-27803

It was discovered that wpa_supplicant does not properly process
P2P (Wi-Fi Direct) provision discovery requests. An attacker
within radio range of the device running P2P could take advantage
of this flaw to cause a denial of service or potentially execute
arbitrary code.

For the stable distribution (buster), these problems have been fixed in
version 2:2.7+git20190128+0c1e29f-6+deb10u3.

We recommend that you upgrade your wpa packages.

For the detailed security status of wpa...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: wpa
CVE ID: CVE-2020-12695 CVE-2021-0326 CVE-2021-27803

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here