ACK: [SRU][J][PATCH 0/1] CVE-2025-27558
Hui Wang
hui.wang at canonical.com
Wed Jun 24 06:36:37 UTC 2026
Acked-by: Hui Wang <hui.wang at canonical.com>
On 6/23/26 17:09, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2025-27558
>
> [ Impact ]
>
> A flaw in the IEEE 802.11 standard allows A-MSDU spoofing attacks against mesh
> networks, a variant of CVE-2020-24588 (FragAttacks) that the original standard
> update failed to address. An adversary can turn a standard MSDU into an A-MSDU,
> injecting arbitrary packets and bypassing frame authentication on mesh
> networks. This affects the mac80211 wireless subsystem and can be exploited to
> spoof traffic in any mesh network deployment.
>
> [ Fix ]
>
> jammy: backported with AI-assisted adaptation
> focal: backported with AI-assisted adaptation
> bionic: backported with AI-assisted adaptation
>
> [ Test Plan ]
>
> Boot tested.
>
> [ Where Problems Could Occur ]
>
> If the fix is incorrect, the mac80211 A-MSDU parsing logic could misclassify
> legitimate mesh frames as attacks and drop them, breaking normal mesh network
> connectivity. Errors in calculating the Mesh Control header length could also
> affect both four-address and six-address mesh configurations.
>
More information about the kernel-team
mailing list