CVE-2022-23304
17.01.2022, 02:15
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.Enginsight
| Vendor | Product | Version |
|---|---|---|
| w1.fi | hostapd | 𝑥 < 2.10 |
| w1.fi | wpa_supplicant | 𝑥 < 2.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References