USN-4734-1: wpa_supplicant and hostapd vulnerabilities
It was discovered that wpasupplicant did not properly handle P2P (Wi-Fi Direct) group information in some situations, leading to a heap overflow. A physically proximate attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-0326) It was discovered that hostapd did not properly handle UPnP subscribe messages in some circumstances. An attacker could use this to cause a denial of service. (CVE-2020-12695)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-4734-1.
What software is affected by this vulnerability?
The wpa_supplicant and hostapd software is affected by this vulnerability.
What is the severity of CVE-2021-0326?
The severity of CVE-2021-0326 is not mentioned in the advisory, but it can lead to a denial of service or possible arbitrary code execution.
How do I fix the vulnerability in hostapd package version 2:2.9-1ubuntu8.1?
To fix the vulnerability in hostapd package version 2:2.9-1ubuntu8.1, update it to version 2:2.9-1ubuntu8.1 by applying the provided remedy.
How do I fix the vulnerability in wpasupplicant package version 2:2.9-1ubuntu8.1?
To fix the vulnerability in wpasupplicant package version 2:2.9-1ubuntu8.1, update it to version 2:2.9-1ubuntu8.1 by applying the provided remedy.