QID 352260

Date Published: 2021-04-05

QID 352260: Amazon Linux Security Advisory for wpa_supplicant: ALAS2-2021-1624

<DIV> Issue Overview:

A flaw was found in the wpa_supplicant, in the way it processes P2P (Wi-Fi Direct) provision discovery requests. This flaw allows an attacker who is within radio range of the device running P2P discovery to cause termination of the wpa_supplicant process or potentially cause code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. (CVE-2021-27803 )

</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please refer to Amazon advisory ALAS-2021-1624 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352260

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1624 Amazon Linux 2 wpa_supplicant (2.6-12.amzn2.2.1) on aarch64 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1624.html
    ALAS-2021-1624 Amazon Linux 2 wpa_supplicant (2.6-12.amzn2.2.1) on i686 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1624.html
    ALAS-2021-1624 Amazon Linux 2 wpa_supplicant (2.6-12.amzn2.2.1) on src URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1624.html
    ALAS-2021-1624 Amazon Linux 2 wpa_supplicant (2.6-12.amzn2.2.1) on x86_64 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1624.html