A flaw was found in the Linux kernels wifi implementation. An attacker within wireless broadcast range can inject custom data into the wireless communication circumventing checks on the data. This can cause the frame to pass checks and be considered a valid frame of a different type.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Kernel-5.4 Extra | kernel | 2022-01-12 19:26 | ALAS2KERNEL-5.4-2022-004 |
Amazon Linux 2 - Kernel-5.10 Extra | kernel | 2022-01-20 23:37 | ALAS2KERNEL-5.10-2022-002 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.3 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
NVD | CVSSv3 | 3.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
NVD | CVSSv2 | 2.9 | AV:A/AC:M/Au:N/C:N/I:P/A:N |