|
|
Log in / Subscribe / Register

P2P most serious, but DoS possible with P2P disabled

P2P most serious, but DoS possible with P2P disabled

Posted Apr 23, 2015 23:11 UTC (Thu) by Duncan (guest, #6647)
In reply to: Wi-Fi software security bug could leave Android, Windows, Linux open to attack (Ars Technica) by BenHutchings
Parent article: Wi-Fi software security bug could leave Android, Windows, Linux open to attack (Ars Technica)

Based on the article, there's either two related bugs, or two triggers for the same bug, depending on how you look at it.

The more serious bug/trigger is apparently in P2P support. It will allow information leakage and potentially allow code execution as well. This one is apparently avoided if P2P support is disabled.

But there's a less serious DOS possibility as well; a crafted SSID could crash WIFI. This one apparently doesn't require P2P and is thus possible regardless of whether it is enabled.

Comments at Ars suggest that unicode SSIDs are an easy way to exceed the buffer, and Alibaba as the source of the discovery would seem to support that. Additionally, a number of Ars users had previously found certain unicode (one commenter) and emoji (another, samsung smart tvs go into an infinite crash/reboot cycle) containing SSIDs did break wifi on some of their equipment, so they simply quit using those types of SSIDs. With this story they believe they now understand the cause.

But I simply RTFA (and comments) and don't claim to be a dev let alone a kernel hacker, so you may well know details I don't?

Regardless, safest to assume at least a DOS is possible without P2P enabled, until we know for certain otherwise.

Duncan


The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds