PublicDateAtUSN: 2021-02-26 23:15:00 UTC Candidate: CVE-2021-27803 PublicDate: 2021-02-26 23:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27803 https://www.openwall.com/lists/oss-security/2021/02/25/3 https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt http://www.openwall.com/lists/oss-security/2021/02/27/1 https://ubuntu.com/security/notices/USN-4757-1 https://ubuntu.com/security/notices/USN-4757-2 Description: A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_wpa: upstream: https://w1.fi/cgit/hostap/commit/src/p2p/p2p_pd.c?id=8460e3230988ef2ec13ce6b69b687e941f6cdb32 upstream: https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-on-PD-R.patch upstream_wpa: released (2:2.9.0-21) precise/esm_wpa: DNE trusty_wpa: ignored (out of standard support) trusty/esm_wpa: released (2.1-0ubuntu1.7+esm4) xenial_wpa: released (2.4-0ubuntu6.8) esm-infra/xenial_wpa: released (2.4-0ubuntu6.8) bionic_wpa: released (2:2.6-15ubuntu2.8) focal_wpa: released (2:2.9-1ubuntu4.3) groovy_wpa: released (2:2.9-1ubuntu8.2) devel_wpa: released (2:2.9.0-21)