CVE-2020-17497: eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4. Patch: https://git.kernel.org/pub/scm/network/wireless/iwd.git/commit/?id=f22ba5aebb569ca54521afd2babdc1f67e3904ea Maintainer, please apply this patch if possible.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a46530b0bdb7fb5d12dbdbe518d52358c6b7c32e commit a46530b0bdb7fb5d12dbdbe518d52358c6b7c32e Author: Ben Kohler <bkohler@gentoo.org> AuthorDate: 2020-08-12 19:35:33 +0000 Commit: Ben Kohler <bkohler@gentoo.org> CommitDate: 2020-08-12 19:35:55 +0000 net-wireless/iwd: add patch for CVE-2020-17497 Bug: https://bugs.gentoo.org/736906 Package-Manager: Portage-3.0.2, Repoman-2.3.23 Signed-off-by: Ben Kohler <bkohler@gentoo.org> .../iwd-1.8-eapol-prevent-key-reinstallation.patch | 73 ++++++++++ net-wireless/iwd/iwd-1.8-r1.ebuild | 156 +++++++++++++++++++++ 2 files changed, 229 insertions(+)
Stabilization being handled in bug 736541.
Tree is clean: commit c7efa5da9a4516ce25e74f4ce9273d5d633506f6 Author: Ben Kohler <bkohler@gentoo.org> Date: Tue Sep 8 07:09:47 2020 -0500 net-wireless/iwd: drop old Package-Manager: Portage-3.0.5, Repoman-3.0.1 Signed-off-by: Ben Kohler <bkohler@gentoo.org> delete mode 100644 net-wireless/iwd/iwd-1.5.ebuild delete mode 100644 net-wireless/iwd/iwd-1.6.ebuild delete mode 100644 net-wireless/iwd/iwd-1.7-r1.ebuild delete mode 100644 net-wireless/iwd/iwd-1.7.ebuild delete mode 100644 net-wireless/iwd/iwd-1.8-r1.ebuild delete mode 100644 net-wireless/iwd/iwd-1.8-r2.ebuild delete mode 100644 net-wireless/iwd/iwd-1.8.ebuild
GLSA Vote: No! Repository is clean, all done.