Information disclosure in hostapd - CVE-2022-37660
Published: March 25, 2025
Vulnerability identifier: #VU106025
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37660
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way hostapd handles PKEX associations. A remote attacker can re-use public keys in order to gain access to sensitive information.
Affected software
hostapd
Ubuntu
hostapd (Ubuntu package)
wpasupplicant (Ubuntu package)
Ubuntu
hostapd (Ubuntu package)
wpasupplicant (Ubuntu package)
How to mitigate CVE-2022-37660
Install updates from vendor's website.
hostapd - update to 2.11
hostapd (Ubuntu package) - addressed in versions 2:2.9-1ubuntu4.6, 2:2.10-6ubuntu2.2, 2:2.10-21ubuntu0.2, 2:2.10-22ubuntu0.1
wpasupplicant (Ubuntu package) - addressed in versions 2:2.9-1ubuntu4.6, 2:2.10-6ubuntu2.2, 2:2.10-21ubuntu0.2, 2:2.10-22ubuntu0.1
hostapd (Ubuntu package) - addressed in versions 2:2.9-1ubuntu4.6, 2:2.10-6ubuntu2.2, 2:2.10-21ubuntu0.2, 2:2.10-22ubuntu0.1
wpasupplicant (Ubuntu package) - addressed in versions 2:2.9-1ubuntu4.6, 2:2.10-6ubuntu2.2, 2:2.10-21ubuntu0.2, 2:2.10-22ubuntu0.1