{"id":"DEBIAN-CVE-2020-24586","details":"The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.","modified":"2026-09-01T16:05:16.030458115Z","published":"2021-05-11T20:15:08.537Z","upstream":["CVE-2020-24586"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2020-24586"}],"affected":[{"package":{"name":"firmware-nonfree","ecosystem":"Debian:12","purl":"pkg:deb/debian/firmware-nonfree?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20210818-1"}]}],"versions":["0.1","0.10","0.11","0.12","0.13","0.13~bpo40+1","0.14","0.14+lenny1","0.14+lenny2","0.15","0.16","0.16~bpo50+1","0.17","0.17~bpo50+1","0.18","0.19","0.2","0.20","0.21","0.22","0.23","0.23~bpo50+1","0.24","0.24~bpo50+1","0.25","0.26","0.27","0.27~bpo50+1","0.28","0.28+squeeze1","0.29","0.3","0.30","0.31","0.32","0.32~bpo60+1","0.33","0.34","0.35","0.35~bpo60+1","0.36","0.36+wheezy.1","0.36+wheezy.1~bpo60+1","0.37","0.38","0.38~bpo70+1","0.39","0.39~bpo70+1","0.4","0.4+etchnhalf.1","0.40","0.40~bpo70+1","0.41","0.41~bpo70+1","0.42","0.43","0.43~bpo70+1","0.44","0.44~bpo8+1","0.4etch1","0.5","0.6","0.7","0.8","0.9","20151018-1","20151018-2","20151018-2~bpo8+1","20151207-1","20151207-1~bpo8+1","20160110-1","20160110-1~bpo8+1","20160824-1","20160824-1~bpo8+1","20161130-1","20161130-2","20161130-2~bpo8+1","20161130-3","20161130-3~bpo8+1","20161130-4","20161130-4~deb8u1","20161130-5","20161130-5~deb8u1","20170823-1","20170823-1~bpo9+1","20180518-1","20180518-1~bpo9+1","20180825+dfsg-1","20180825+dfsg-1~bpo9+1","20180825-1","20190114-1","20190114-1~bpo9+1","20190114-1~bpo9+2","20190114-2","20190114-2~bpo9+1","20190114-2~deb9u1","20190502-1","20190717-1","20190717-2","20190717-2~bpo10+1","20200421-1","20200619-1","20200619-1~bpo10+1","20200721-1","20200721-1~bpo10+1","20200817-1","20200817-1~bpo10+1","20200918-1","20200918-1~bpo10+1","20201022-1","20201118-1","20201218-1","20201218-2","20201218-3","20210208-1","20210208-2","20210208-3","20210208-4","20210208-4~bpo10+1","20210315-1","20210315-1~exp1","20210315-2","20210315-2~bpo10+1","20210315-3","20210315-3~bpo10+1","20210322-1~exp1","20210427-1","20210511-1","20210511-1~exp1","20210716-1~exp1","20210818-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2020-24586.json"}},{"package":{"name":"firmware-nonfree","ecosystem":"Debian:13","purl":"pkg:deb/debian/firmware-nonfree?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20210818-1"}]}],"versions":["0.1","0.10","0.11","0.12","0.13","0.13~bpo40+1","0.14","0.14+lenny1","0.14+lenny2","0.15","0.16","0.16~bpo50+1","0.17","0.17~bpo50+1","0.18","0.19","0.2","0.20","0.21","0.22","0.23","0.23~bpo50+1","0.24","0.24~bpo50+1","0.25","0.26","0.27","0.27~bpo50+1","0.28","0.28+squeeze1","0.29","0.3","0.30","0.31","0.32","0.32~bpo60+1","0.33","0.34","0.35","0.35~bpo60+1","0.36","0.36+wheezy.1","0.36+wheezy.1~bpo60+1","0.37","0.38","0.38~bpo70+1","0.39","0.39~bpo70+1","0.4","0.4+etchnhalf.1","0.40","0.40~bpo70+1","0.41","0.41~bpo70+1","0.42","0.43","0.43~bpo70+1","0.44","0.44~bpo8+1","0.4etch1","0.5","0.6","0.7","0.8","0.9","20151018-1","20151018-2","20151018-2~bpo8+1","20151207-1","20151207-1~bpo8+1","20160110-1","20160110-1~bpo8+1","20160824-1","20160824-1~bpo8+1","20161130-1","20161130-2","20161130-2~bpo8+1","20161130-3","20161130-3~bpo8+1","20161130-4","20161130-4~deb8u1","20161130-5","20161130-5~deb8u1","20170823-1","20170823-1~bpo9+1","20180518-1","20180518-1~bpo9+1","20180825+dfsg-1","20180825+dfsg-1~bpo9+1","20180825-1","20190114-1","20190114-1~bpo9+1","20190114-1~bpo9+2","20190114-2","20190114-2~bpo9+1","20190114-2~deb9u1","20190502-1","20190717-1","20190717-2","20190717-2~bpo10+1","20200421-1","20200619-1","20200619-1~bpo10+1","20200721-1","20200721-1~bpo10+1","20200817-1","20200817-1~bpo10+1","20200918-1","20200918-1~bpo10+1","20201022-1","20201118-1","20201218-1","20201218-2","20201218-3","20210208-1","20210208-2","20210208-3","20210208-4","20210208-4~bpo10+1","20210315-1","20210315-1~exp1","20210315-2","20210315-2~bpo10+1","20210315-3","20210315-3~bpo10+1","20210322-1~exp1","20210427-1","20210511-1","20210511-1~exp1","20210716-1~exp1","20210818-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2020-24586.json"}},{"package":{"name":"firmware-nonfree","ecosystem":"Debian:14","purl":"pkg:deb/debian/firmware-nonfree?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20210818-1"}]}],"versions":["0.1","0.10","0.11","0.12","0.13","0.13~bpo40+1","0.14","0.14+lenny1","0.14+lenny2","0.15","0.16","0.16~bpo50+1","0.17","0.17~bpo50+1","0.18","0.19","0.2","0.20","0.21","0.22","0.23","0.23~bpo50+1","0.24","0.24~bpo50+1","0.25","0.26","0.27","0.27~bpo50+1","0.28","0.28+squeeze1","0.29","0.3","0.30","0.31","0.32","0.32~bpo60+1","0.33","0.34","0.35","0.35~bpo60+1","0.36","0.36+wheezy.1","0.36+wheezy.1~bpo60+1","0.37","0.38","0.38~bpo70+1","0.39","0.39~bpo70+1","0.4","0.4+etchnhalf.1","0.40","0.40~bpo70+1","0.41","0.41~bpo70+1","0.42","0.43","0.43~bpo70+1","0.44","0.44~bpo8+1","0.4etch1","0.5","0.6","0.7","0.8","0.9","20151018-1","20151018-2","20151018-2~bpo8+1","20151207-1","20151207-1~bpo8+1","20160110-1","20160110-1~bpo8+1","20160824-1","20160824-1~bpo8+1","20161130-1","20161130-2","20161130-2~bpo8+1","20161130-3","20161130-3~bpo8+1","20161130-4","20161130-4~deb8u1","20161130-5","20161130-5~deb8u1","20170823-1","20170823-1~bpo9+1","20180518-1","20180518-1~bpo9+1","20180825+dfsg-1","20180825+dfsg-1~bpo9+1","20180825-1","20190114-1","20190114-1~bpo9+1","20190114-1~bpo9+2","20190114-2","20190114-2~bpo9+1","20190114-2~deb9u1","20190502-1","20190717-1","20190717-2","20190717-2~bpo10+1","20200421-1","20200619-1","20200619-1~bpo10+1","20200721-1","20200721-1~bpo10+1","20200817-1","20200817-1~bpo10+1","20200918-1","20200918-1~bpo10+1","20201022-1","20201118-1","20201218-1","20201218-2","20201218-3","20210208-1","20210208-2","20210208-3","20210208-4","20210208-4~bpo10+1","20210315-1","20210315-1~exp1","20210315-2","20210315-2~bpo10+1","20210315-3","20210315-3~bpo10+1","20210322-1~exp1","20210427-1","20210511-1","20210511-1~exp1","20210716-1~exp1","20210818-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2020-24586.json"}},{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2020-24586.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2020-24586.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2020-24586.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}