Executive brief
A vulnerability in the Linux kernel's Wi-Fi implementation could allow an attacker within range of a mesh network to bypass security protections. By spoofing specific types of network traffic (A-MSDU frames), an attacker could potentially inject malicious data or intercept communications. This issue is a variant of the 'FragAttacks' vulnerabilities and specifically impacts the security of mesh-based wireless networks.
Technical details
This vulnerability is a variant of CVE-2020-24588 (FragAttacks) specifically affecting IEEE 802.11 mesh networks. The root cause is an insufficient validation of Aggregate MAC Service Data Unit (A-MSDU) frames, where an adversary can maliciously convert a standard MSDU into an A-MSDU. The mitigation involves parsing received A-MSDUs as standard MSDUs to detect the presence of an RFC1042 header at an unexpected offset determined by the Mesh Control header length. An attacker within radio range (adjacent) can exploit this without authentication to perform frame injection or data interception. Patches have been released for multiple stable kernel branches including 6.1.x, 6.6.x, 6.12.x, and 6.15.x.
Affected products
- Linux Linux Kernel 6.1.107 to 6.1.146, 6.3 to 6.15.7
Timeline
- 2025-08-16: disclosed: Initial advisory publication
- 2025-07-17: patched: Fix committed to stable kernel tree
References
- https://git.kernel.org/stable/c/6e3b09402cc6c3e3474fa548e8adf6897dda05de
- https://git.kernel.org/stable/c/737bb912ebbe4571195c56eba557c4d7315b26fb
- https://git.kernel.org/stable/c/e01851f6e9a665a6011b14714b271d3e6b0b8d32
- https://git.kernel.org/stable/c/e2c8a3c0388aef6bfc4aabfba07bc7dff16eea80
- https://git.kernel.org/stable/c/ec6392061de6681148b63ee6c8744da833498cdd
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html