CVE-2025-27558

Aliases:UBUNTU-CVE-2025-27558DEBIAN-CVE-2025-27558
Advisory lineage Upstream: 0 Downstream: 22
Deferred
Published: 21 May 2025, 00:00
Last modified:03 Nov 2025, 17:32

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (cve.org)
EPSS Score
0.29% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 May 2025, 00:00
Published
Vulnerability first disclosed
03 Nov 2025, 17:32
Last Modified
Vulnerability information updated

Description

IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.

CVSS Metrics

  • v4.0MEDIUMScore: 5.3CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.29% Percentile: 22%

Techniques & Countermeasures

  • CWE-345Insufficient Verification of Data Authenticity

    The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Systems

  • debianlinux

    all | < 6.1.147-1 | < 6.12.41-1 | < 6.16.3-1

  • debianlinux-6.1

    < 6.1.153-1~deb11u1

  • ubuntulinux

    all | < 4.15.0-254.266 | < 5.4.0-234.254 | < 5.15.0-187.197 | < 6.8.0-100.100

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 4.15.0-1195.208 | < 5.4.0-1162.173 | < 5.15.0-1113.120 | < 6.8.0-1046.49

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all | < 5.15.0-1114.121~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all | < 5.4.0-1162.173~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    < 6.14.0-1017.17~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1046.49~22.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2133.139 | all | < 5.15.0-1113.120+fips1 | < 6.8.0-1046.49+fips1

  • ubuntulinux-aws-hwe

    all | < 4.15.0-1195.208~16.04.1

  • ubuntulinux-azure

    all | < 4.15.0-1205.220~14.04.1 | < 4.15.0-1205.220~16.04.1 | all | < 5.4.0-1167.173 | < 5.15.0-1118.127 | < 6.8.0-1046.52

  • ubuntulinux-azure-4.15

    < 4.15.0-1205.220

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all | < 5.15.0-1119.128~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    all | < 5.4.0-1167.173~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    < 6.14.0-1017.17~24.04.1

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1051.57~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | < 5.15.0-1118.127 | all | all

  • ubuntulinux-azure-fde-5.15

    all | < 5.15.0-1118.127~20.04.1

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.14

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2113.119 | < 5.4.0-1167.173+fips1 | all | < 5.15.0-1118.127+fips1 | < 6.8.0-1046.52+fips1

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-azure-nvidia-6.14

    all

  • ubuntulinux-bluefield

    all | all | < 5.4.0-1121.128 | < 5.15.0-1097.99 | < 6.8.0-1016.20

  • ubuntulinux-fips

    < 4.15.0-1150.162 | < 5.4.0-1136.146 | all | < 5.15.0-190.200+fips1 | < 6.8.0-100.100+fips1

  • ubuntulinux-gcp

    all | all | < 4.15.0-1188.205~16.04.1 | all | < 5.4.0-1165.174 | < 5.15.0-1114.124 | < 6.8.0-1047.50

  • ubuntulinux-gcp-4.15

    < 4.15.0-1188.205

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    all | < 5.15.0-1114.124~20.04.1

Showing first 50 affected entries in server-rendered view.

References (23)