VDB
CVE-2021-3587
CVE-2021-3587
PUBLISHED
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Timeline
- Jun 24, 2021 CVE Published
- Mar 1, 2024 PoC Published
- Mar 1, 2024 PoC Published
- Apr 23, 2024 PoC Published
- May 19, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Sep 6, 2024 PoC Published
- Sep 19, 2025 PoC Published
- Nov 17, 2025 PoC Published
- Mar 20, 2026 PoC Published
- Mar 29, 2026 Distribution Patch
- Mar 29, 2026 Distribution Patch
References
- https://www.debian.org/lts/security/2021/dla-2689 advisory
- https://www.debian.org/lts/security/2021/dla-2690 advisory
- https://ubuntu.com/security/notices/USN-5044-1 advisory
- https://ubuntu.com/security/notices/LSN-0080-1 advisory
- https://ubuntu.com/security/notices/USN-5046-1 advisory
- https://ubuntu.com/security/notices/USN-5045-1 advisory
- https://ubuntu.com/security/notices/USN-5014-1 advisory
- https://ubuntu.com/security/notices/USN-5016-1 advisory
- https://ubuntu.com/security/notices/USN-5017-1 advisory
- https://ubuntu.com/security/notices/USN-5018-1 advisory
- https://ubuntu.com/security/notices/USN-5015-1 advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00473.html url
- 20210511 Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021 vendor-advisory
- https://www.fragattacks.com url
- https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md url
- [oss-security] 20210511 various 802.11 security issues - fragattacks.com mailing-list
- [debian-lts-announce] 20210623 [SECURITY] [DLA 2689-1] linux security update mailing-list
- [debian-lts-announce] 20210623 [SECURITY] [DLA 2690-1] linux-4.19 security update mailing-list
- https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 url
- [debian-lts-announce] 20230401 [SECURITY] [DLA 3380-1] firmware-nonfree LTS new upstream version (security updates and newer firmware for Linux 5.10) mailing-list