CVE-2019-11555NULL Pointer Dereference in Hostapd

Severity
5.9MEDIUMNVD
EPSS
13.7%
top 5.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 26
Latest updateMay 24

Description

The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDw1.fi/hostapd< 2.8

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3r3j-9m7c-h35g: The EAP-pwd implementation in hostapd (EAP server) before 22022-05-24
CVEList
CVE-2019-11555: The EAP-pwd implementation in hostapd (EAP server) before 22019-04-26
OSV
CVE-2019-11555: The EAP-pwd implementation in hostapd (EAP server) before 22019-04-26

📋Vendor Advisories

5
BSD
FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant2019-05-14
Ubuntu
wpa_supplicant and hostapd vulnerability2019-05-09
Ubuntu
wpa_supplicant and hostapd vulnerability2019-05-07
Red Hat
wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation2019-04-18
Debian
CVE-2019-11555: wpa - The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant...2019

💬Community

4
Bugzilla
CVE-2019-11555 hostapd: wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation [epel-all]2019-05-22
Bugzilla
CVE-2019-11555 hostapd: wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation [fedora-all]2019-05-22
Bugzilla
CVE-2019-11555 wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation [fedora-all]2019-04-26
Bugzilla
CVE-2019-11555 wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation2019-04-26
CVE-2019-11555 — NULL Pointer Dereference in Hostapd | cvebase