CVE-2019-5061

NameCVE-2019-5061
DescriptionAn exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wpa (PTS)jessie, jessie (lts)2.3-1+deb8u14vulnerable
stretch (security)2:2.4-1+deb9u9vulnerable
stretch (lts), stretch2:2.4-1+deb9u10vulnerable
buster2:2.7+git20190128+0c1e29f-6+deb10u3vulnerable
buster (security)2:2.7+git20190128+0c1e29f-6+deb10u4vulnerable
bullseye2:2.9.0-21fixed
bookworm2:2.10-12fixed
sid, trixie2:2.10-21fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wpasourcewheezy(unfixed)end-of-life
wpasource(unstable)2:2.9+git20200213+877d9a0-1unimportant

Notes

https://talosintelligence.com/vulnerability_reports/TALOS-2019-0849
https://w1.fi/cgit/hostap/commit/?id=018edec9b2bd3db20605117c32ff79c1e625c432
removes IAPP functionality from hostapd. IAPP implementation furthermore
was never really completed on wpa side and this obsoleted functionality in
hostapd had been moved to the kernel driver already.

Search for package or bug name: Reporting problems