Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2024-83657584b3 Critical WLAN Credential Leak Alert

fedora
Calendar Grey August 3, 2024
Dist Fedora Esm H88
The latest version of wpa_supplicant, 2.11, resolves SSID issues in Fedora 40 by introducing essential updates and critical security enhancements.
Update to upstream version 2.11.

Summary

wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support

for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA

component that is used in the client stations. It implements key negotiation

with a WPA Authenticator and it controls the roaming and IEEE 802.11

authentication/association of the wlan driver.

Update Information:

Update to upstream version 2.11.

Change Log

* Mon Jul 29 2024 Davide Caratti - 1:2.11-1 - Update to version 2.11 (#2299036) - Disable OpenSSL ENGINE API (#2301368)

References


[ 1 ] Bug #2293095 - CVE-2023-52424 wpa_supplicant: 802.11: SSID Confusion attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2293095 [ 2 ] Bug #2293097 - CVE-2023-52424 hostapd: 802.11: SSID Confusion attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2293097 [ 3 ] Bug #2299036 - wpa_supplicant-2.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2299036 [ 4 ] Bug #2299039 - hostapd-2.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2299039 [ 5 ] Bug #2301368 - wpa_supplicant: FTBFS in Fedora rawhide/f41 https://bugzilla.redhat.com/show_bug.cgi?id=2301368

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-73626281d8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: wpa_supplicant
Product: Fedora 40
Version: 2.11
Release: 1.fc40
Summary: WPA/WPA2/IEEE 802.1X Supplicant

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here