Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 426
Alerts This Week
Warning Icon 1 426

SUSE wpa_supplicant Moderate Security Risk CVE-2025-24912 CVE-2026-58374

suse
Calendar Grey July 17, 2026
Scroller Suse
Updates for wpa_supplicant resolve two identified issues enhancing network authentication security.
A security update for wpa_supplicant addresses two vulnerabilities, CVE-2025-24912 and CVE-2026-58374, affecting multiple SUSE Linux products; available through standard installati...

Summary

## This update for wpa_supplicant fixes the following issues: * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ * Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like

References

* bsc#1239461

* bsc#1269892

Cross-

* CVE-2025-24912

* CVE-2026-58374

CVSS scores:

* CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-58374 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-58374 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-58374 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Products:

* Basesystem Module 15-SP7

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP7

* SUSE Linux Enterprise Server 15 SP7

* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves two vulnerabilities can now be installed.

##

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3103-1
Release Date: 2026-07-17T13:30:13Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.