PT-2022-5940 · Hostap+7 · Hostapd+7

Published

2022-01-16

·

Updated

2025-04-12

·

CVE-2022-23303

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions hostapd versions prior to 2.10 wpa supplicant versions prior to 2.10
Description The issue is related to an incomplete fix, resulting in side channel attacks due to cache access patterns. This allows an attacker to potentially disclose protected information. The vulnerability is associated with the implementations of SAE in hostapd and wpa supplicant.
Recommendations For hostapd versions prior to 2.10, update to version 2.10 or later to resolve the issue. For wpa supplicant versions prior to 2.10, update to version 2.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the SAE implementation in hostapd and wpa supplicant until a patch is available.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1159
ALT-PU-2022-1160
ALT-PU-2022-1927
ALT-PU-2022-1980
ALT-PU-2022-2423
ALT-PU-2023-1833
AZL-7747
BDU:2022-07363
CVE-2022-23303
DLA-4123-1
MGASA-2022-0025
OESA-2022-1510
OPENSUSE-SU-2022:0716-1
OPENSUSE-SU-2022_0716-1
ROSA-SA-2023-2311
ROSA-SA-2024-2367
SUSE-SU-2022:0504-1
SUSE-SU-2022:0716-1
SUSE-SU-2022:0716-2
SUSE-SU-2022:1853-1
SUSE-SU-2022_0504-1
SUSE-SU-2022_0716-1
USN-7317-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Suse
Ubuntu
Hostapd
Wpa Supplicant