CVE-2022-23303
Description
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description wpa_supplicant: SAE side channel attacks as a result of cache access patterns CVSS v3: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 9wpa_supplicant-1:2.10-2.el9RHBA-2022:39912022-05-17T00:00:00Z Package state ProductPackageState Red Hat Enterprise Linux 6wpa_supplicantOut of support scope Red Hatβ¦
Description
wpa_supplicant: SAE side channel attacks as a result of cache access patterns
CVSS v3: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | wpa_supplicant-1:2.10-2.el9 | RHBA-2022:3991 | 2022-05-17T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | wpa_supplicant | Out of support scope |
| Red Hat Enterprise Linux 7 | wpa_supplicant | Not affected |
| Red Hat Enterprise Linux 8 | wpa_supplicant | Not affected |
Apply commands
yum update -y wpa_supplicant
# or:
dnf upgrade -y wpa_supplicant
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| sles | affected | | |
| debian | bookworm | fixed | 2:2.10-1 |
| debian | bullseye | fixed | 2:2.9.0-21+deb11u3 |
| debian | forky | fixed | 2:2.10-1 |
| debian | sid | fixed | 2:2.10-1 |
| debian | trixie | fixed | 2:2.10-1 |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.