
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-0326 is a vulnerability discovered in the p2p_copy_client_info function of p2p.c, affecting Android versions 8.1 through 11 and wpa_supplicant implementations. The vulnerability was disclosed in February 2021 and involves a possible out-of-bounds write due to a missing bounds check (NVD, CVE).
The vulnerability exists in the P2P (Wi-Fi Direct) group information processing functionality. Specifically, the flaw occurs in the p2p_copy_client_info function where a missing bounds check can lead to an out-of-bounds write condition. The issue has been assigned a CVSS v3.1 base score of 7.5 (High), with attack vector being Adjacent, attack complexity High, and no privileges or user interaction required (Ubuntu).
If exploited, this vulnerability could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. The impact includes potential arbitrary code execution, denial of service of the wpa_supplicant process, or system compromise (Debian, Red Hat).
The vulnerability can be exploited by an attacker within radio range of the vulnerable system by sending specially crafted management frames that trigger a P2P peer interaction. No user interaction is required for exploitation, making it particularly concerning for devices with Wi-Fi Direct capabilities enabled (Red Hat).
Vendors have released security updates to address this vulnerability. Red Hat has released wpa_supplicant version 2.9-5 for RHEL 8, Debian has issued updates in version 2:2.4-1+deb9u8 for Debian 9, and Ubuntu has provided fixes across multiple releases. Users are strongly advised to update their systems with the latest security patches (Red Hat, Debian LTS).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."