PT-2021-3058 · Netbsd+8 · Netbsd+8

Mathy Vanhoef

·

Published

2021-05-11

·

Updated

2022-09-30

·

CVE-2020-26139

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NetBSD version 7.1
Description An issue was discovered in the kernel where an Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients. The vulnerability is related to the implementation of the Extensible Authentication Protocol over LAN (EAPOL) and is associated with deficiencies in the authentication procedure, which could allow a remote attacker to cause a denial of service.
Recommendations For NetBSD version 7.1, consider disabling the EAPOL frame forwarding feature until a patch is available to prevent potential denial-of-service attacks. Restrict access to the network to minimize the risk of exploitation. Avoid using the affected kernel in projected Wi-Fi networks until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4356
BDU:2021-02664
CESA-2021_4140
CESA-2021_4356
CVE-2020-26139
DLA-2689-1
DLA-2690-1
MGASA-2021-0257
MGASA-2021-0258
OPENSUSE-SU-2021:0843-1
OPENSUSE-SU-2021:0947-1
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_0843-1
OPENSUSE-SU-2021_0947-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
RHSA-2021:4140
RHSA-2021:4356
RHSA-2021_4140
RHSA-2021_4356
SUSE-SU-2021:14764-1
SUSE-SU-2021:1887-1
SUSE-SU-2021:1888-1
SUSE-SU-2021:1889-1
SUSE-SU-2021:1890-1
SUSE-SU-2021:1891-1
SUSE-SU-2021:1899-1
SUSE-SU-2021:1912-1
SUSE-SU-2021:1913-1
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021:2208-1
SUSE-SU-2021:2406-1
SUSE-SU-2021:2421-1
SUSE-SU-2021:2451-1
SUSE-SU-2021_14764-1
USN-4997-1
USN-4997-2
USN-4999-1
USN-5000-1
USN-5000-2
USN-5001-1
USN-5018-1
USN-5343-1

Affected Products

Almalinux
Astra Linux
Centos
Check Point Gaia
Linuxmint
Netbsd
Red Hat
Suse
Ubuntu