hostapd: * SAE changes - disable use of groups using Brainpool curves - improved protection against side channel attacks [https://w1.fi/security/2019-6/] * EAP-pwd changes - disable use of groups using Brainpool curves - improved protection against side channel attacks [https://w1.fi/security/2019-6/] * fixed FT-EAP initial mobility domain association using PMKSA caching * added configuration of airtime policy * fixed FILS to and RSNE into (Re)Association Response frames * fixed DPP bootstrapping URI parser of channel list * added support for regulatory WMM limitation (for ETSI) * added support for MACsec Key Agreement using IEEE 802.1X/PSK * added experimental support for EAP-TEAP server (RFC 7170) * added experimental support for EAP-TLS server with TLS v1.3 * added support for two server certificates/keys (RSA/ECC) * added AKMSuiteSelector into "STA <addr>" control interface data to determine with AKM was used for an association * added eap_sim_id parameter to allow EAP-SIM/AKA server pseudonym and fast reauthentication use to be disabled * fixed an ECDH operation corner case with OpenSSL
Thanks for update. Will do ASAP.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6ff6b0539ddd74b3f7c10a7c226d85754572a9fb commit 6ff6b0539ddd74b3f7c10a7c226d85754572a9fb Author: Andrey Utkin <andrey_utkin@gentoo.org> AuthorDate: 2019-08-13 12:46:59 +0000 Commit: Andrey Utkin <andrey_utkin@gentoo.org> CommitDate: 2019-08-13 13:08:12 +0000 net-wireless/hostapd: add new version 2.9 Bug: https://bugs.gentoo.org/692060 Package-Manager: Portage-2.3.66, Repoman-2.3.16 Signed-off-by: Andrey Utkin <andrey_utkin@gentoo.org> net-wireless/hostapd/Manifest | 1 + net-wireless/hostapd/hostapd-2.9.ebuild | 262 ++++++++++++++++++++++++++++++++ 2 files changed, 263 insertions(+)
So there are security aspects, and stabilization should be rushed. I guess 1 week of being in testing status would be good, after that I will call for stabilization.
Created rush stablereq ticket https://bugs.gentoo.org/692540