[SRU][J][PATCH 0/1] CVE-2025-27558
Cengiz Can
cengiz.can at canonical.com
Tue Jun 23 09:09:39 UTC 2026
https://ubuntu.com/security/CVE-2025-27558
[ Impact ]
A flaw in the IEEE 802.11 standard allows A-MSDU spoofing attacks against mesh
networks, a variant of CVE-2020-24588 (FragAttacks) that the original standard
update failed to address. An adversary can turn a standard MSDU into an A-MSDU,
injecting arbitrary packets and bypassing frame authentication on mesh
networks. This affects the mac80211 wireless subsystem and can be exploited to
spoof traffic in any mesh network deployment.
[ Fix ]
jammy: backported with AI-assisted adaptation
focal: backported with AI-assisted adaptation
bionic: backported with AI-assisted adaptation
[ Test Plan ]
Boot tested.
[ Where Problems Could Occur ]
If the fix is incorrect, the mac80211 A-MSDU parsing logic could misclassify
legitimate mesh frames as attacks and drop them, breaking normal mesh network
connectivity. Errors in calculating the Mesh Control header length could also
affect both four-address and six-address mesh configurations.
More information about the kernel-team
mailing list