Vulnerability in wpa_supplicant allowing remote code execution

A vulnerability (CVE-2021-27803) has been identified in the wpa_supplicant package, used for connecting to wireless networks in many Linux, *BSD, and Android distributions, which could potentially be exploited to execute attacker code when processing specially crafted Wi-Fi Direct (Wi-Fi P2P) management frames. To launch an attack, an attacker must be within the wireless network's range to send the victim a specially formatted frame set.

The issue is caused by an error in the Wi-Fi P2P handler, where processing an incorrectly formatted PDR (Provision Discovery Request) frame can lead to a state where an old P2P peer record is deleted and information is written to an already freed memory block (use-after-free). The vulnerability affects wpa_supplicant releases from 1.0 to 2.9 compiled with the CONFIG_P2P option.

The vulnerability will be addressed in wpa_supplicant release 2.10. The fix has been published in the Fedora Linux distribution. The status of updates from other distributions can be tracked on the following pages: Debian, Ubuntu, RHEL, SUSE, Arch Linux. As a workaround to block the vulnerability, simply disable P2P support by setting 'p2p_disabled=1' in the configuration or executing the command 'P2P_SET disabled 1' in the CLI interface.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster