CVE-2015-5316: Null Pointer Dereference
The eappwdperformconfirmexchange function in eappeer/eappwd.c in wpasupplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an EAP-pwd Confirm message followed by the Identity exchange.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5316?
CVE-2015-5316 has been classified as a denial of service vulnerability due to a NULL pointer dereference leading to a daemon crash.
How do I fix CVE-2015-5316?
Upgrading to wpa_supplicant version 2.6 or later will resolve the vulnerability associated with CVE-2015-5316.
Which versions of wpa_supplicant are affected by CVE-2015-5316?
wpa_supplicant versions prior to 2.6 are affected by CVE-2015-5316.
What type of attack does CVE-2015-5316 exploit?
CVE-2015-5316 can be exploited by sending a specially crafted EAP-pwd Confirm message.
Is CVE-2015-5316 specific to any operating system?
CVE-2015-5316 impacts primarily Debian GNU/Linux versions 8.0 with wpa_supplicant configured for EAP-pwd.