PT-2022-5941 · Hostap+7 · Hostapd+7

Published

2022-01-16

·

Updated

2025-04-12

·

CVE-2022-23304

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions hostapd versions prior to 2.10 wpa supplicant versions prior to 2.10
Description The issue is related to the implementations of EAP-pwd in hostapd and wpa supplicant, which are vulnerable to side-channel attacks due to cache access patterns. This vulnerability allows a remote attacker to disclose protected information.
Recommendations For hostapd versions prior to 2.10, update to version 2.10 or later. For wpa supplicant versions prior to 2.10, update to version 2.10 or later.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1159
ALT-PU-2022-1160
ALT-PU-2022-1927
ALT-PU-2022-1980
ALT-PU-2022-2423
ALT-PU-2023-1833
AZL-7748
BDU:2022-07364
CVE-2022-23304
DLA-4123-1
OESA-2022-1510
OPENSUSE-SU-2022:0716-1
OPENSUSE-SU-2022_0716-1
ROSA-SA-2023-2311
ROSA-SA-2024-2367
SUSE-SU-2022:0504-1
SUSE-SU-2022:0716-1
SUSE-SU-2022:0716-2
SUSE-SU-2022:1853-1
USN-7317-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Suse
Ubuntu
Hostapd
Wpa Supplicant