Vulnerability Description
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| W1.Fi | Wpa Supplicant | >= 1.0, < 2.10 |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 9.0 |
References
- http://www.openwall.com/lists/oss-security/2021/02/27/1Mailing ListMitigationThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00003.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-PatchVendor Advisory
- https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-MitigationVendor Advisory
- https://www.debian.org/security/2021/dsa-4898Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/02/25/3Mailing ListMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/02/27/1Mailing ListMitigationThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00003.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-PatchVendor Advisory
FAQ
What is CVE-2021-27803?
CVE-2021-27803 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potent...
How severe is CVE-2021-27803?
CVE-2021-27803 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27803?
Check the references section above for vendor advisories and patch information. Affected products include: W1.Fi Wpa Supplicant, Fedoraproject Fedora, Debian Debian Linux.