ALT-BU-2023-3612-1
Branch c9f2 update bulletin.
Package wpa_supplicant updated to version 2.10-alt2 for branch c9f2 in task 321127.
Closed vulnerabilities
BDU:2019-04775
Уязвимость компонента защищённого доступа Wi-Fi WPA Supplicant, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01584
Уязвимость компонента p2p/p2p_pd.c клиента защищённого доступа Wi-Fi WPA Supplicant, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2022-07363
Уязвимость реализации SAE клиента защищённого доступа Wi-Fi WPA Supplicant, связанная с раскрытием информации через несоответствие, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-07364
Уязвимость реализации EAP-pwd клиента защищённого доступа Wi-Fi WPA Supplicant, связанная с раскрытием информации через несоответствие, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2024-11-21
CVE-2019-16275
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- FEDORA-2019-0e0b28001d
- FEDORA-2019-0e0b28001d
- FEDORA-2019-65509aac53
- FEDORA-2019-65509aac53
- FEDORA-2019-740834c559
- FEDORA-2019-740834c559
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2265b5ae86
- FEDORA-2019-2265b5ae86
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- USN-4136-1
- USN-4136-1
- USN-4136-2
- USN-4136-2
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- DSA-4538
- DSA-4538
- https://www.openwall.com/lists/oss-security/2019/09/11/7
- https://www.openwall.com/lists/oss-security/2019/09/11/7
Modified: 2024-11-21
CVE-2021-27803
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.
- [oss-security] 20210227 Re: wpa_supplicant P2P provision discovery processing vulnerability
- [oss-security] 20210227 Re: wpa_supplicant P2P provision discovery processing vulnerability
- [debian-lts-announce] 20210302 [SECURITY] [DLA 2581-1] wpa security update
- [debian-lts-announce] 20210302 [SECURITY] [DLA 2581-1] wpa security update
- FEDORA-2021-99cad2b81f
- FEDORA-2021-99cad2b81f
- FEDORA-2021-3430f96019
- FEDORA-2021-3430f96019
- FEDORA-2021-9b00febe54
- FEDORA-2021-9b00febe54
- https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-on-PD-R.patch
- https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-on-PD-R.patch
- https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt
- https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt
- DSA-4898
- DSA-4898
- https://www.openwall.com/lists/oss-security/2021/02/25/3
- https://www.openwall.com/lists/oss-security/2021/02/25/3
Modified: 2024-11-21
CVE-2021-30004
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
Modified: 2024-11-21
CVE-2022-23303
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
Modified: 2024-11-21
CVE-2022-23304
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
Closed bugs
Не работает wi-fi на ноутбуке после обновления wpa_supplicant до 2.10-alt1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-26570
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
- [oss-security] 20201124 OpenSC 0.21.0 released
- [oss-security] 20201124 OpenSC 0.21.0 released
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24316
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24316
- https://github.com/OpenSC/OpenSC/commit/6903aebfddc466d966c7b865fae34572bf3ed23e
- https://github.com/OpenSC/OpenSC/commit/6903aebfddc466d966c7b865fae34572bf3ed23e
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- FEDORA-2020-7c80831ffe
- FEDORA-2020-7c80831ffe
Modified: 2024-11-21
CVE-2020-26571
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
- [oss-security] 20201124 OpenSC 0.21.0 released
- [oss-security] 20201124 OpenSC 0.21.0 released
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20612
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20612
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- FEDORA-2020-7c80831ffe
- FEDORA-2020-7c80831ffe
Modified: 2024-11-21
CVE-2020-26572
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
- [oss-security] 20201124 OpenSC 0.21.0 released
- [oss-security] 20201124 OpenSC 0.21.0 released
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22967
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22967
- https://github.com/OpenSC/OpenSC/commit/9d294de90d1cc66956389856e60b6944b27b4817
- https://github.com/OpenSC/OpenSC/commit/9d294de90d1cc66956389856e60b6944b27b4817
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- FEDORA-2020-7c80831ffe
- FEDORA-2020-7c80831ffe
Modified: 2024-11-21
CVE-2021-42778
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28185
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28185
- https://bugzilla.redhat.com/show_bug.cgi?id=2016083
- https://bugzilla.redhat.com/show_bug.cgi?id=2016083
- https://github.com/OpenSC/OpenSC/commit/f015746d
- https://github.com/OpenSC/OpenSC/commit/f015746d
- GLSA-202209-03
- GLSA-202209-03
Modified: 2024-11-21
CVE-2021-42779
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28843
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28843
- https://bugzilla.redhat.com/show_bug.cgi?id=2016086
- https://bugzilla.redhat.com/show_bug.cgi?id=2016086
- https://github.com/OpenSC/OpenSC/commit/1db88374
- https://github.com/OpenSC/OpenSC/commit/1db88374
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- GLSA-202209-03
- GLSA-202209-03
Modified: 2024-11-21
CVE-2021-42780
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28383
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28383
- https://bugzilla.redhat.com/show_bug.cgi?id=2016139
- https://bugzilla.redhat.com/show_bug.cgi?id=2016139
- https://github.com/OpenSC/OpenSC/commit/5df913b7
- https://github.com/OpenSC/OpenSC/commit/5df913b7
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- GLSA-202209-03
- GLSA-202209-03
Modified: 2024-11-21
CVE-2021-42781
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
- https://bugzilla.redhat.com/show_bug.cgi?id=2016439
- https://bugzilla.redhat.com/show_bug.cgi?id=2016439
- https://github.com/OpenSC/OpenSC/commit/05648b06
- https://github.com/OpenSC/OpenSC/commit/05648b06
- https://github.com/OpenSC/OpenSC/commit/17d8980c
- https://github.com/OpenSC/OpenSC/commit/17d8980c
- https://github.com/OpenSC/OpenSC/commit/40c50a3a
- https://github.com/OpenSC/OpenSC/commit/40c50a3a
- https://github.com/OpenSC/OpenSC/commit/5d4daf6c
- https://github.com/OpenSC/OpenSC/commit/5d4daf6c
- https://github.com/OpenSC/OpenSC/commit/cae5c71f
- https://github.com/OpenSC/OpenSC/commit/cae5c71f
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- GLSA-202209-03
- GLSA-202209-03
Modified: 2024-11-21
CVE-2021-42782
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
- https://bugzilla.redhat.com/show_bug.cgi?id=2016448
- https://bugzilla.redhat.com/show_bug.cgi?id=2016448
- https://github.com/OpenSC/OpenSC/commit/1252aca9
- https://github.com/OpenSC/OpenSC/commit/1252aca9
- https://github.com/OpenSC/OpenSC/commit/456ac566
- https://github.com/OpenSC/OpenSC/commit/456ac566
- https://github.com/OpenSC/OpenSC/commit/7114fb71
- https://github.com/OpenSC/OpenSC/commit/7114fb71
- https://github.com/OpenSC/OpenSC/commit/78cdab94
- https://github.com/OpenSC/OpenSC/commit/78cdab94
- https://github.com/OpenSC/OpenSC/commit/ae1cf0be
- https://github.com/OpenSC/OpenSC/commit/ae1cf0be
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- GLSA-202209-03
- GLSA-202209-03