Input validation error in wpa_supplicant and hostapd - CVE-2019-16275
Published: September 30, 2019 / Updated: September 30, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the affected software allows an incorrect indication of disconnection in certain situations because source address validation is mishandled. A remote attacker in radio range of the access point can send a specially crafted 802.11 frame and cause a denial of service condition on target system.
Affected software
hostapd
busybox (Alpine package)
wpa (Debian package)
hostapd (Alpine package)
wpa_supplicant (Alpine package)
wpa_supplicant
hostapd
Fedora
Slackware Linux
How to mitigate CVE-2019-16275
hostapd (Alpine package) - update to 2.6-r6
wpa_supplicant (Alpine package) - update to 2.6-r11
wpa_supplicant - addressed in versions 2.7-2.fc29, 2.8-3.fc30, 2.9-2.fc31
hostapd - addressed in versions 2.9-2.el7, 2.9-2.fc30, 2.9-2.fc31
External References
- http://www.openwall.com/lists/oss-security/2019/09/12/6
- https://lists.debian.org/debian-lts-announce/2019/09/msg00017.html
- https://usn.ubuntu.com/4136-1/
- https://usn.ubuntu.com/4136-2/
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- https://www.openwall.com/lists/oss-security/2019/09/11/7
Related Security Bulletins
- Debian update for wpa
- Input validation error in wpa_supplicant (Alpine package)
- Input validation error in hostapd (Alpine package)
- Input validation error in busybox (Alpine package)
- Slackware update for wpa_supplicant
- Fedora 31 update for hostapd
- Fedora 30 update for hostapd
- Fedora EPEL 7 update for hostapd
- Fedora 31 update for wpa_supplicant
- Fedora 30 update for wpa_supplicant
- Fedora 29 update for wpa_supplicant