NULL pointer dereference in hostapd - CVE-2019-11555

 

NULL pointer dereference in hostapd - CVE-2019-11555

Published: April 27, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31083
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11555
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c. A remote attacker can perform a denial of service (DoS) attack.


Affected software

hostapd
Gentoo Linux
Fedora
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
busybox (Alpine package)
hostapd (Alpine package)
wpa_supplicant (Alpine package)
firefox-esr (Alpine package)
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource

How to mitigate CVE-2019-11555

Update to version 2.8.

hostapd - update to 2.8
hostapd (Alpine package) - update to 2.6-r4
wpa_supplicant (Alpine package) - update to 2.6-r10
hostapd - addressed in versions 2.8-1.el7, 2.8-1.fc29, 2.8-1.fc30, 2.9-1.el7
wpa_supplicant - update to 2.8-2.fc30
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1

External References

Related Security Bulletins