NULL pointer dereference in hostapd - CVE-2019-11555
Published: April 27, 2019 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c. A remote attacker can perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Fedora
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
busybox (Alpine package)
hostapd (Alpine package)
wpa_supplicant (Alpine package)
firefox-esr (Alpine package)
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
How to mitigate CVE-2019-11555
hostapd (Alpine package) - update to 2.6-r4
wpa_supplicant (Alpine package) - update to 2.6-r10
hostapd - addressed in versions 2.8-1.el7, 2.8-1.fc29, 2.8-1.fc30, 2.9-1.el7
wpa_supplicant - update to 2.8-2.fc30
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
External References
- http://www.openwall.com/lists/oss-security/2019/04/26/1
- https://lists.debian.org/debian-lts-announce/2019/07/msg00030.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5T7G763UECWR7FQXOJVL67PW7C5A3SA4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DJKZHAT5KPUN26JL77EUH563GAH5XZ5C/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQ6P2GI5GSXRNLNIUNPARFZQVDEIGVZD/
- https://seclists.org/bugtraq/2019/May/40
- https://seclists.org/bugtraq/2019/May/64
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.asc
- https://security.gentoo.org/glsa/201908-25
- https://usn.ubuntu.com/3969-1/
- https://usn.ubuntu.com/3969-2/
- https://w1.fi/security/2019-5/
- https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt
- https://www.debian.org/security/2019/dsa-4450
- https://www.openwall.com/lists/oss-security/2019/04/18/6
Related Security Bulletins
- NULL pointer dereference in hostapd
- NULL pointer dereference in wpa_supplicant (Alpine package)
- NULL pointer dereference in hostapd (Alpine package)
- NULL pointer dereference in busybox (Alpine package)
- Gentoo update for hostapd and wpa_supplicant
- NULL pointer dereference in firefox-esr (Alpine package)
- SUSE update for wpa_supplicant
- Fedora 30 update for wpa_supplicant
- Fedora 30 update for hostapd
- Fedora EPEL 7 update for hostapd
- Fedora 29 update for hostapd
- Fedora EPEL 7 update for hostapd