Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33011
HistoryNov 17, 2021 - 10:37 p.m.

Network Packet Injection

2021-11-1722:37:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.001 Low

EPSS

Percentile

35.8%

kernel-rt is vulnerable to network package injection. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. A flaw was found in the Linux kernel, where the WiFi implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (ex., LLC/SNAP) header for EAPOL. The highest threat from this vulnerability is to integrity.