Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 692540 - <net-wireless/hostapd-2.9: SAE/EAP-pwd side-channel attack
Summary: <net-wireless/hostapd-2.9: SAE/EAP-pwd side-channel attack
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Andriy Utkin (RETIRED)
URL: https://w1.fi/security/2019-6/sae-eap...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-08-19 17:34 UTC by Andriy Utkin (RETIRED)
Modified: 2020-02-11 23:44 UTC (History)
0 users

See Also:
Package list:
net-wireless/hostapd-2.9
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andriy Utkin (RETIRED) gentoo-dev 2019-08-19 17:34:25 UTC
Main changes since 2.9 include security fixes:

hostapd:
* SAE changes
  - disable use of groups using Brainpool curves
  - improved protection against side channel attacks
  [https://w1.fi/security/2019-6/]
* EAP-pwd changes
  - disable use of groups using Brainpool curves
  - improved protection against side channel attacks
  [https://w1.fi/security/2019-6/]
* fixed FT-EAP initial mobility domain association using PMKSA caching
* added configuration of airtime policy
* fixed FILS to and RSNE into (Re)Association Response frames
* fixed DPP bootstrapping URI parser of channel list
* added support for regulatory WMM limitation (for ETSI)
* added support for MACsec Key Agreement using IEEE 802.1X/PSK
* added experimental support for EAP-TEAP server (RFC 7170)
* added experimental support for EAP-TLS server with TLS v1.3
* added support for two server certificates/keys (RSA/ECC)
* added AKMSuiteSelector into "STA <addr>" control interface data to
  determine with AKM was used for an association
* added eap_sim_id parameter to allow EAP-SIM/AKA server pseudonym and
  fast reauthentication use to be disabled
* fixed an ECDH operation corner case with OpenSSL

Thanks in advance.
Comment 1 Andriy Utkin (RETIRED) gentoo-dev 2019-08-19 17:36:19 UTC
The package has been in the tree for 6 days.

Calling for stabilization this early because of security aspect.
Comment 2 Agostino Sarubbo gentoo-dev 2019-08-19 20:05:29 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2019-08-20 22:55:19 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2019-08-22 22:02:10 UTC
ppc stable
Comment 5 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-09-01 18:24:04 UTC
arm stable
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2020-02-11 23:44:06 UTC
GLSA Vote: No

Repository is clean, all done.