Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Slackware: 2021-362-01 Critical: wpa_supplicant Denial Of Service

slackware
Calendar Grey December 28, 2021
Dist Slackware Esm H88
Exciting updates for wpa_supplicant have been rolled out in Slackware, addressing critical vulnerabilities such as potential denial of service and additional concerns.
New wpa_supplicant packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/wpa_supplicant-2.9-i586-1_slack14.2.txz: Upgraded. This update fixes the following security issues: AP mode PMF disconnection protection bypass. UPnP SUBSCRIBE misbehavior in hostapd WPS AP. P2P group information processing vulnerability. P2P provision discovery processing vulnerability. ASN.1: Validate DigestAlgorithmIdentifier parameters. Flush pending control interface message for an interface to be removed. These issues could result in a denial-of-service, privilege escalation, arbitrary code execution, or other unexpected behavior. Thanks to nobodino for pointing out the patches. For more information, see: https://www.cve.org/CVERecord?id=CVE-2021-0326 https://www.cve.org/CVERecord?id=CVE-2021-0535 https://www.cve.org/CVERecord?id=CVE-2020-12695 https://www.cve.org/CVERecord?id=CVE-2019-16275 https://www.cve.org/CVERecord?id=CVE-2021-27803

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.0 package: c7f924f06b8d72768571d8304f5c37e7 wpa_supplicant-2.9-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 993052fe0c17c01c57a68f1e7ead6254 wpa_supplicant-2.9-x86_64-1_slack14.0.txz
Slackware 14.1 package: fa383478bd07b1e7ae7d86b253b21375 wpa_supplicant-2.9-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 200d9c2a29cb6fa65ac997ce2e585dbd wpa_supplicant-2.9-x86_64-1_slack14.1.txz
Slackware 14.2 package: dcdc508c0b81f2101786ce35fc083c7b wpa_supplicant-2.9-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: 50e4302b46ba90b9b6801c68b5f9a155 wpa_supplicant-2.9-x86_64-1_slack14.2.txz
Slackware -current package: ca90b2f1ab0b20a3001a02269528dd78 n/wpa_supplicant-2.9-i586-8.txz
Slackware x86_64 -current package: 34e0822856e122fbbfbd9c5bbffd6762 n/wpa_supplicant-2.9-x86_64-8.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg wpa_supplicant-2.9-i586-1_slack14.2.txz

Your message here