Out-of-bounds write in wpa_supplicant - CVE-2021-0326

 

Out-of-bounds write in wpa_supplicant - CVE-2021-0326

Published: December 29, 2021 / Updated: February 10, 2022


Vulnerability identifier: #VU59104
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0326
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input within the p2p_copy_client_info() function of p2p.c in wpa_suplicant. A remote attacker pass specially crafted input to the application, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

wpa_supplicant
Debian Linux
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Slackware Linux
Ubuntu
openEuler
Fedora
Dell Hybrid Client
hostapd (Ubuntu package)
wpasupplicant (Ubuntu package)
wpa_supplicant-help
wpa_supplicant-gui
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
wpa_supplicant
wpa (Debian package)
wpa_supplicant (Red Hat package)

How to mitigate CVE-2021-0326

Install update from vendor's website.

wpa_supplicant - update to 2.10
hostapd (Ubuntu package) - addressed in versions 1:2.1-0ubuntu1.7+esm3, 1:2.4-0ubuntu6.7, 2:2.6-15ubuntu2.7, 2:2.9-1ubuntu4.2, 2:2.9-1ubuntu8.1
wpasupplicant (Ubuntu package) - addressed in versions 2.1-0ubuntu1.7+esm3, 2.4-0ubuntu6.7, 2:2.6-15ubuntu2.7, 2:2.9-1ubuntu4.2, 2:2.9-1ubuntu8.1
wpa_supplicant-help - update to 2.6-29
wpa_supplicant-gui - update to 2.6-29
wpa_supplicant-debuginfo - update to 2.6-29
wpa_supplicant-debugsource - update to 2.6-29
wpa_supplicant - update to 2.6-29
wpa (Debian package) - update to 2:2.7+git20190128+0c1e29f-6+deb10u3
wpa_supplicant (Red Hat package) - update to 2.9-5.el8
wpa_supplicant - addressed in versions 2.9-5.fc32, 2.9-7.fc33, 2.9-11.fc34
wpa_supplicant-debugsource - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant - update to 2.9-15.22.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins