AI for Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2021-0326
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-0326 is a vulnerability discovered in the p2p_copy_client_info function of p2p.c, affecting Android versions 8.1 through 11 and wpa_supplicant implementations. The vulnerability was disclosed in February 2021 and involves a possible out-of-bounds write due to a missing bounds check (NVD, CVE).

Technical details

The vulnerability exists in the P2P (Wi-Fi Direct) group information processing functionality. Specifically, the flaw occurs in the p2p_copy_client_info function where a missing bounds check can lead to an out-of-bounds write condition. The issue has been assigned a CVSS v3.1 base score of 7.5 (High), with attack vector being Adjacent, attack complexity High, and no privileges or user interaction required (Ubuntu).

Impact

If exploited, this vulnerability could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. The impact includes potential arbitrary code execution, denial of service of the wpa_supplicant process, or system compromise (Debian, Red Hat).

Exploitability

The vulnerability can be exploited by an attacker within radio range of the vulnerable system by sending specially crafted management frames that trigger a P2P peer interaction. No user interaction is required for exploitation, making it particularly concerning for devices with Wi-Fi Direct capabilities enabled (Red Hat).

Mitigation and workarounds

Vendors have released security updates to address this vulnerability. Red Hat has released wpa_supplicant version 2.9-5 for RHEL 8, Debian has issued updates in version 2:2.4-1+deb9u8 for Debian 9, and Ubuntu has provided fixes across multiple releases. Users are strongly advised to update their systems with the latest security patches (Red Hat, Debian LTS).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

wpa_supplicant: 2.9-r10

Fixed

v3.18

wpa_supplicant: 2.9-r10

Fixed

v3.19

wpa_supplicant: 2.9-r10

Fixed

v3.20

wpa_supplicant: 2.9-r10

Fixed

v3.21

wpa_supplicant: 2.9-r10

Fixed

v3.22

wpa_supplicant: 2.9-r10

Fixed

v3.23

wpa_supplicant: 2.9-r10

Fixed

Arch Linux

Fixed

rolling

wpa_supplicant: 2:2.9-8

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85706CRITICAL10
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
YesYesSep 12, 2026
CVE-2026-88009HIGH8.8
  • NixOS logoNixOS
  • traefik-3
NoYesSep 10, 2026
CVE-2026-88008HIGH7
  • NixOS logoNixOS
  • traefik
NoYesSep 10, 2026
CVE-2026-88012MEDIUM5.3
  • NixOS logoNixOS
  • cpe:2.3:a:traefik:traefik
NoYesSep 10, 2026
CVE-2026-88011MEDIUM5.3
  • NixOS logoNixOS
  • traefik-fips-3
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management