RHSA-2018:3107: Moderate: wpa_supplicant security and bug fix update
The wpasupplicant packages contain an 802.1X Supplicant with support for WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication methods. They implement key negotiation with a WPA Authenticator for client stations and controls the roaming and IEEE 802.11 authentication and association of the WLAN driver.Security Fix(es): wpasupplicant: Unauthenticated EAPOL-Key decryption in wpasupplicant (CVE-2018-14526) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:3107?
The severity of RHSA-2018:3107 is classified as important.
How do I fix RHSA-2018:3107?
To fix RHSA-2018:3107, update the wpa_supplicant package to the latest version provided by your vendor.
What vulnerabilities are addressed in RHSA-2018:3107?
RHSA-2018:3107 addresses multiple security vulnerabilities found in the wpa_supplicant packages.
Who is affected by RHSA-2018:3107?
All users and systems running vulnerable versions of the wpa_supplicant package are affected by RHSA-2018:3107.
What actions should I take if I am affected by RHSA-2018:3107?
If you are affected by RHSA-2018:3107, you should promptly apply the necessary updates to mitigate the risks.