Critical Security Advisory for Hostapd 2.11 in Fedora 40
Summary
hostapd is a user space daemon for access point and authentication servers. It
implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP
Authenticators and RADIUS authentication server.
hostapd is designed to be a "daemon" program that runs in the back-ground and
acts as the backend component controlling authentication. hostapd supports
separate frontend programs and an example text-based frontend, hostapd_cli, is
included with hostapd.
Update Information:
Update to upstream version 2.11.
Change Log
* Mon Jul 29 2024 Davide Caratti
References
[ 1 ] Bug #2293095 - CVE-2023-52424 wpa_supplicant: 802.11: SSID Confusion attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2293095
[ 2 ] Bug #2293097 - CVE-2023-52424 hostapd: 802.11: SSID Confusion attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2293097
[ 3 ] Bug #2299036 - wpa_supplicant-2.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2299036
[ 4 ] Bug #2299039 - hostapd-2.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2299039
[ 5 ] Bug #2301368 - wpa_supplicant: FTBFS in Fedora rawhide/f41
https://bugzilla.redhat.com/show_bug.cgi?id=2301368
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-73626281d8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label