Back

LOW

kernel: Reassembling fragments encrypted under different keys

Published May 11, 2021

Description

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published May 11, 2021
Updated Aug 4, 2024
Reserved Aug 21, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 11, 2021
Bugzilla 1959654

ENISA EUVD

Assigner mitre
Published May 11, 2021
Updated Aug 4, 2024

GitHub

No data