CVE-2022-23304
17.01.2022, 02:15
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.Enginsight
Vendor | Product | Version |
---|---|---|
w1.fi | hostapd | 𝑥 < 2.10 |
w1.fi | wpa_supplicant | 𝑥 < 2.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References