Input validation error in wpa_supplicant - CVE-2021-30004
Published: December 29, 2021 / Updated: January 17, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to insufficient validation of user-supplied input in tls/pkcs1.c and tls/x509v3.c files in wpa_supplicant and hostapd when handling AlgorithmIdentifier parameters. A remote attacker can pass specially crafted input to the application and perform MitM attack.
Affected software
Gentoo Linux
SUSE MicroOS
SUSE Linux Enterprise Server
Slackware Linux
SUSE Linux Enterprise Module for Basesystem
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
net-wireless/hostapd
Dell EMC PowerStore Family Operating System
RecoverPoint Classic
PowerScale OneFS
How to mitigate CVE-2021-30004
wpa_supplicant - addressed in versions 2.9-4.29.1, 2.9-23.12.1
wpa_supplicant-debuginfo - addressed in versions 2.9-4.29.1, 2.9-23.12.1
wpa_supplicant-debugsource - addressed in versions 2.9-4.29.1, 2.9-23.12.1
net-wireless/hostapd - update to 2.10
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
RecoverPoint Classic - update to 5.1 SP4 P5
PowerScale OneFS - update to 12.0
External References
Related Security Bulletins
- MitM attack in wpa_supplicant
- MitM attack in hostapd
- Slackware update for wpa_supplicant
- SUSE update for wpa_supplicant
- SUSE update for wpa_supplicant
- Gentoo update for wpa_supplicant, hostapd
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Dell RecoverPoint Classic