CVE-2020-26144 PUBLISHED

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

EPSS 1.02% · 77.0th percentile

Risk Scores

EPSS Score
1.02%
77.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-aws-5.135.13.0-1011.12~20.04.1, 5.13.0-1008.9~20.04.2, 0
Ubuntu:18.04:LTSlinux-aws-5.30, 5.3.0-1016.17~18.04.1, 5.3.0-1017.18~18.04.1
Ubuntu:20.04:LTSlinux-azure-5.85.8.0-1042.45~20.04.1, 5.8.0-1043.46~20.04.1, 5.8.0-1033.35~20.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-fips4.15.0-1011.12, 0
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-azure-fips5.4.0-1137.144+fips1, 5.4.0-1138.145+fips1, 5.4.0-1139.146+fips1
Ubuntu:Pro:20.04:LTSlinux-kvm5.4.0-1051.53, 5.4.0-1053.55, 5.4.0-1054.56
Ubuntu:Pro:18.04:LTSlinux-oracle-5.45.4.0-1133.142~18.04.1, 5.4.0-1044.47~18.04.1, 5.4.0-1046.50~18.04.2
Ubuntu:18.04:LTSlinux-hwe4.18.0-25.26~18.04.1, 4.18.0-20.21~18.04.1, 4.18.0-18.19~18.04.1
Ubuntu:22.04:LTSlinux-riscv5.13.0-1006.6+22.04.1, 5.13.0-1004.4, 0
Ubuntu:Pro:18.04:LTSlinux-oracle4.15.0-1008.10, 0, 4.15.0-1007.9
Ubuntu:20.04:LTSlinux-azure-5.135.13.0-1013.15~20.04.1, 5.13.0-1014.16~20.04.1, 5.13.0-1017.19~20.04.1
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:Pro:20.04:LTSlinux-xilinx-zynqmp5.4.0-1035.39, 5.4.0-1036.40, 5.4.0-1037.41
Ubuntu:Pro:18.04:LTSlinux-aws4.15.0-1169.182, 4.15.0-1188.201, 4.15.0-1187.200
Ubuntu:20.04:LTSlinux-oracle-5.135.13.0-1036.43~20.04.1, 5.13.0-1034.40~20.04.1, 5.13.0-1033.39~20.04.1
Ubuntu:Pro:18.04:LTSlinux-raspi-5.45.4.0-1050.56~18.04.1, 5.4.0-1052.58~18.04.1, 5.4.0-1053.60~18.04.1
Ubuntu:Pro:18.04:LTSlinux-gcp-5.45.4.0-1058.62~18.04.1, 5.4.0-1145.154~18.04.1, 5.4.0-1143.152~18.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1103.109+cvm1.1, 5.4.0-1100.106+cvm1.1, 5.4.0-1098.104+cvm1.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips4.15.0-2033.37, 4.15.0-2035.39, 4.15.0-2036.40

…and 80 more

Timeline

References

Open in Interactive Console →