CVE-2020-26142 PUBLISHED

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.

EPSS 1.53% · 81.2th percentile

Risk Scores

EPSS Score
1.53%
81.2th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10linux-riscv0, 6.17.0-8.8.1, 6.17.0-12.12.1
Ubuntu:Pro:18.04:LTSlinux-ibm-5.45.4.0-1095.100~18.04.1, 5.4.0-1077.82~18.04.1, 5.4.0-1078.83~18.04.1
Ubuntu:18.04:LTSlinux-oracle-5.05.0.0-1008.13~18.04.1, 5.0.0-1009.14~18.04.1, 5.0.0-1011.16
Ubuntu:20.04:LTSlinux-riscv5.4.0-39.44, 5.4.0-40.45, 5.4.0-36.41
Ubuntu:Pro:FIPS-updates:22.04:LTSlinux-fips5.15.0-119.129+fips1, *, *
Ubuntu:Pro:18.04:LTSlinux4.15.0-230.242, 4.15.0-202.213, 4.15.0-200.211
Ubuntu:Pro:20.04:LTSlinux-oracle-5.155.15.0-1035.41~20.04.1, 5.15.0-1054.60~20.04.1, 5.15.0-1055.61~20.04.1
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-fips0, 5.4.0-1026.30, 5.4.0-1028.32
Ubuntu:Pro:18.04:LTSlinux-gcp-4.154.15.0-1158.175, 4.15.0-1160.177, 4.15.0-1161.178
Ubuntu:24.04:LTSlinux-ibm6.5.0-1009.9, 6.8.0-1045.45, 6.8.0-1026.26
Ubuntu:Pro:FIPS:20.04:LTSlinux-aws-fips5.4.0-1021.21+fips2, 0
Ubuntu:20.04:LTSlinux-gkeop-5.15*, *, *
Ubuntu:22.04:LTSlinux-gcp-6.56.5.0-1011.11~22.04.1, 6.5.0-1013.13~22.04.1, 6.5.0-1014.14~22.04.1
Ubuntu:22.04:LTSlinux-ibm5.15.0-1059.62, 5.15.0-1090.93, 5.15.0-1072.75
Ubuntu:Pro:FIPS-preview:22.04:LTSlinux-azure-fips0, 5.15.0-1053.61+fips1
Ubuntu:22.04:LTSlinux-nvidia-tegra-igx5.15.0-1005.5, 5.15.0-1006.6, 5.15.0-1007.7
Ubuntu:Pro:20.04:LTSlinux-iot5.4.0-1035.36, 5.4.0-1034.35, 5.4.0-1001.3
Ubuntu:22.04:LTSlinux-kvm5.15.0-1084.89, 5.15.0-1059.64, 5.15.0-1020.24
Ubuntu:Pro:18.04:LTSlinux-oracle4.15.0-1011.13, 4.15.0-1057.62, 4.15.0-1106.117
Ubuntu:22.04:LTSlinux-aws-6.86.8.0-1044.46~22.04.1, 6.8.0-1031.33~22.04.1, 6.8.0-1032.34~22.04.1

…and 219 more

Timeline

References

Open in Interactive Console →