Skip to content
Commit 13ae7a3f authored by Steve Sakoman's avatar Steve Sakoman
Browse files

wpa-supplicant: fix CVE-2022-23303-4

The implementations of SAE in hostapd before 2.10 and wpa_supplicant
before 2.10 are vulnerable to side channel attacks as a result
of cache access patterns. NOTE: this issue exists because of an
incomplete fix for CVE-2019-9494.

Backport patches from:
https://w1.fi/security/2022-1/



CVE: CVE-2022-23303 CVE-2022-23304

Signed-off-by: default avatarSteve Sakoman <steve@sakoman.com>
parent 8eb4fdd1
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment