Debian 10480 Published by

A WPA security update has been issued for Debian GNU/Linux 10 (Buster) Extended LTS:

ELA-1419-1 wpa security update




ELA-1419-1 wpa security update


Package : wpa

Version : 2:2.9.0-21+deb11u3~deb10u1 (buster)

Related CVEs :
CVE-2022-23303
CVE-2022-23304
CVE-2022-37660

Multiple vulnerabilities were found in wpa, a set of tools including
the widely-used wpasupplicant client for authenticating with WPA
and WPA2 wireless networks.

CVE-2022-23303
The implementations of SAE in hostapd
are vulnerable to side channel attacks as a result of
cache access patterns.

CVE-2022-23304
The implementations of EAP-pwd are vulnerable
to side-channel attacks as a result of cache access patterns.

CVE-2022-37660
The PKEX code remains active even after
a successful PKEX association. An attacker that successfully
bootstrapped public keys with another entity using PKEX in
the past, will be able to subvert a future bootstrapping
by passively observing public keys.


ELA-1419-1 wpa security update