CVE-2024-5290: High severity wpa_supplicant vulnerability
An issue was discovered in Ubuntu wpasupplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpasupplicant runs as (usually root).
Membership in the netdev group or access to the dbus interface of wpasupplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpasupplicant process; other escalation paths might exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5290?
CVE-2024-5290 is classified as a high severity vulnerability that allows local unprivileged attackers to escalate their privileges.
How do I fix CVE-2024-5290?
To fix CVE-2024-5290, upgrade the wpa_supplicant package to a version that is not vulnerable, such as 2:2.9.0-21+deb11u2, 2:2.10-12+deb12u2, or 2:2.10-22.
Who is affected by CVE-2024-5290?
CVE-2024-5290 affects users running vulnerable versions of wpa_supplicant on Ubuntu systems.
What systems are impacted by CVE-2024-5290?
CVE-2024-5290 primarily impacts Ubuntu Linux systems that utilize the wpa_supplicant package.
What types of attacks are possible with CVE-2024-5290?
CVE-2024-5290 allows local attackers to load arbitrary shared objects, leading to potential privilege escalation.