CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually ro...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 22, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJul 14, 2026 Jan 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for C...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJul 14, 2026 Jan 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2...Show more |
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c. |
3Debian FedoraprojectW1.fi3Debian Linux FedoraWpa SupplicantJun 17, 2026 Feb 26, 2021 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of a...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreJun 17, 2026 Sep 12, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more |
1W1.fi 2Hostapd Wpa SupplicantJun 17, 2026 Apr 26, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received....Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacke...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authenticatio...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE su...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. Th...Show more |
5Fedoraproject FreebsdOpensuse+2 more8Backports Sle FedoraFreebsd+5 moreJun 17, 2026 Apr 17, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information f...Show more |
3Canonical DebianW1.fi3Debian Linux Ubuntu LinuxWpa SupplicantNov 21, 2024 Aug 8, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the A...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration p...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attac...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within...Show more |