Candidate: CVE-2020-17497 PublicDate: 2020-08-12 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17497 https://lists.01.org/hyperkitty/list/iwd@lists.01.org/thread/4GUXL4Z6KZWWZINATGHNJVAEUTS3I7PG/ https://git.kernel.org/pub/scm/network/wireless/iwd.git/commit/?id=f22ba5aebb569ca54521afd2babdc1f67e3904ea Description: eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=968996 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N [8.1 HIGH] Patches_iwd: upstream_iwd: released (1.9-1) precise/esm_iwd: DNE trusty_iwd: ignored (out of standard support) trusty/esm_iwd: DNE xenial_iwd: DNE bionic_iwd: DNE focal_iwd: needs-triage groovy_iwd: ignored (reached end-of-life) hirsute_iwd: not-affected (1.9-2) impish_iwd: not-affected (1.9-2) jammy_iwd: not-affected (1.9-2) devel_iwd: not-affected (1.9-2)