CVE-2020-26145 – kernel: accepting plaintext broadcast fragments as full frames
https://notcve.org/view.php?id=CVE-2020-26145
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. Se detectó un problema en los dispositivos Samsung Galaxy S3 i9305 versión 4.4.4. Las implementaciones de WEP, WPA, WPA2 y WPA3 aceptan segundos fragmentos de transmisión (o posteriores) incluso cuando se envían en texto plano y los procesan como tramas completas no fragmentados. • http://www.openwall.com/lists/oss-security/2021/05/11/12 https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md https://www.fragattacks.com https://access.redhat.com/security/cve/CVE-2020-26145 https://bugzilla.redhat.com/show_bug.cgi?id=1960500 • CWE-20: Improper Input Validation CWE-307: Improper Restriction of Excessive Authentication Attempts •