Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 7, 8 - MGASA-2021-0095 Critical: wpa_supplicant Denial Of Service

mageia
Calendar Grey March 2, 2021
Dist Mageia Esm H88
Mageia 2021-0096 resolves a significant vulnerability in NetworkManager impacting various versions.
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests

Summary

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range (CVE-2021-27803).

References

- https://bugs.mageia.org/show_bug.cgi?id=28438

- https://www.openwall.com/lists/oss-security/2021/02/27/1

- https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt

- https://www.cve.org/CVERecord?id=CVE-2021-27803

Resolution

SRPMS

- 7/core/wpa_supplicant-2.9-1.4.mga7

- 8/core/wpa_supplicant-2.9-8.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0095.html
Type: security
CVE: CVE-2021-27803

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here