Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 5.10, < 5.10.193
A vulnerability in the Linux kernel's MACsec implementation allows for indefinite replay of frames under certain conditions. This issue arises when the packet number (PN) is at its maximum value, causing an overflow that disrupts proper sequence number handling. As a result, an attacker can capture and replay frames, exploiting the MACsec decryption process to reconstruct the same initialization vector (IV) and potentially interfere with secure communications.
The vulnerability allows an attacker to replay captured MACsec frames indefinitely, disrupting secure communications by causing the receiver to process the same frame multiple times as if it were new.
To reproduce this vulnerability, send a MACsec frame with a packet number (PN) of 0xFFFFFFFF. The receiver will not properly advance its sequence number, allowing the frame to be replayed indefinitely.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.