shield
Security update for wpa_supplicant
SUSE-SLE-Module-Basesystem-15-SP7-2026-3103
This update for wpa_supplicant fixes the following issues: - CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). - CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/
-
Release DateJul 17 2026
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.7 x86_64
-
Packages
Basesystem Module 15.7 s390x
-
Packages
Basesystem Module 15.7 ppc64le
-
Packages
Basesystem Module 15.7 aarch64
-
Packages