Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 937483 (CVE-2024-5290) - net-wireless/wpa_supplicant: possible privilege escalation
Summary: net-wireless/wpa_supplicant: possible privilege escalation
Status: UNCONFIRMED
Alias: CVE-2024-5290
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://ubuntu.com/security/CVE-2024-...
Whiteboard: A1 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2024-08-07 07:19 UTC by foufou33
Modified: 2024-08-12 06:46 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description foufou33 2024-08-07 07:19:58 UTC
fom debian/ubuntu 
CVE-2024-5290
An issue was discovered in wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root).

Patch available here: https://launchpadlibrarian.net/742553699/wpa_2%3A2.10-21_2%3A2.10-21ubuntu0.1.diff.gz

Reproducible: Always
Comment 1 foufou33 2024-08-07 07:21:12 UTC
Debian's DSA https://security-tracker.debian.org/tracker/DSA-5739-1