Critical Linux Kernel Vulnerabilities Expose WiFi Systems to Injection Attacks

Critical Linux Kernel Vulnerabilities Expose WiFi Systems to Injection Attacks

First seen 2 Sep 2026, 22:13 UTC UbuntuLinuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been discovered in the Linux kernel affecting various distributions, including Ubuntu 20.04 and 18.04. Researchers Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef identified that the WiFi implementation fails to handle aggregated frames in mesh networks, allowing a physically proximate attacker to inject packets (CVE-2025-27558). The vulnerabilities impact several subsystems, including x86 architecture, InfiniBand drivers, and network protocols. Users are urged to update their systems immediately to mitigate risks. The flaws were disclosed on September 2, 2026, and are part of a broader set of security issues affecting the Linux kernel. Affected systems include those running on Oracle Cloud and AWS. After applying the updates, a system reboot is necessary to implement changes. The vulnerabilities are critical, requiring urgent attention from system administrators.

Key Points: • Critical vulnerabilities in the Linux kernel allow WiFi packet injection. • CVE-2025-27558 is the primary CVE associated with this issue. • Immediate updates and system reboots are required to mitigate risks.

Ask AI about this cluster

Timeline

2021-05-11
CVE-2020-24588 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-21
CVE-2021-47378 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-21
CVE-2025-27558 published
A vulnerability in the Linux kernel's WiFi implementation was disclosed, allowing packet injection.
Ubuntu
2026-03-25
CVE-2026-23392 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-06
CVE-2026-31405 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-13
CVE-2026-31414 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-22
CVE-2026-31448 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-24
CVE-2026-31657 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-24
CVE-2026-31668 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31705 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE