Logo
componentwpa-supplicant
Name
wpa-supplicant
Version
2.11
Type
library
Description
Client for Wi-Fi Protected Access (WPA)
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:*:wpa_supplicant:2.11:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
2.10
scarthgap
2.10

Patches#


#
Title
Author
Resolve
1
defconfig: Uncomment CONFIG_IEEE80211BE=y
Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>
2
RADIUS: Drop pending request only when accepting the response
Jouni Malinen <j@w1.fi>
CVE-2025-24912
3
WNM: Extend workaround for broken AP operating class behavior
"Yu Zhang(Yuriy)" <quic_yuzha@quicinc.com>
4
macsec_linux: Hardware offload requires Linux headers >= v5.7
Sergey Matyukevich <geomatsi@gmail.com>
5
defconfig: Document IEEE 802.11be as a published
Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>
6
RADIUS: Fix pending request dropping
Jouni Malinen <quic_jouni@quicinc.com>
CVE-2025-24912
7
defconfig: Update Opportunistic Wireless Encryption (OWE)
Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>

Vulnerabilities#


Name
Analysis
Description
Patched
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
False Positive
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.