https://seclists.org/oss-sec/2026/q2/1076: hostapd: OOB write in Wi-Fi 7 MLD association parsing (p-auth DoS)
Published Jun 30, 2026
·Updated
Affected Software
1 affected component
Hostapd Hostapd>2.11<2.12
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is considered high due to the potential for out-of-bounds writes leading to denial of service.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, update to the latest version of hostapd that includes the security patch addressing the MLD parsing issue.
3
What impact does CVE-2026-XXXX have on users?
CVE-2026-XXXX could allow unauthorized access or denial of service in Wi-Fi 7 deployments.
4
In which software is CVE-2026-XXXX found?
CVE-2026-XXXX is found in hostapd, particularly in its AP mode functionality.
5
What versions of hostapd are affected by CVE-2026-XXXX?
Versions of hostapd prior to the upstream fixed release are affected by CVE-2026-XXXX.