Opened 2 years ago

Closed 2 years ago

Last modified 2 years ago

#5138 closed enhancement (fixed)

linux-6.0.2

Reported by: pierre Owned by: lfs-book
Priority: high Milestone: 11.3
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

New point version. Looks like there are several CVE's fixed in the WiFi stack: See https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.2 (search "CVE") and https://www.openwall.com/lists/oss-security/2022/10/13/5 for details and PoC. Note that all those CVE's need an attacker able to inject forged packets.

Change History (3)

comment:1 by ken@…, 2 years ago

I've seen a comment that just scanning for networks can expose you (the forged packets are beacon frames), so potentially any use of wifi.

comment:2 by Bruce Dubbs, 2 years ago

Resolution: fixed
Status: newclosed

Updates at commit c5d10b5af.

comment:3 by Douglas R. Reno, 2 years ago

Filed SA-11.2-016

Note: See TracTickets for help on using tickets.