ALPINE-CVE-2019-9496

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 17 Apr 2019, 14:29
Last modified:03 Dec 2025, 22:45

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
3.0 (osv_alpine)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Apr 2019, 14:29
Published
Vulnerability first disclosed
03 Dec 2025, 22:45
Last Modified
Vulnerability information updated

Description

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

CVSS Metrics

  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Systems

  • alpinehostapd

    < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.8-r0 | < 2.6-r3 | < 2.6-r5 | < 2.6-r6 | < 2.7-r3

References (1)