Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade hostapd | Aug 30, 2017 | Oct 10, 2012 |
| Debian | — | Upgrade wpa | Jul 30, 2024 | Oct 10, 2012 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Nov 24, 2012 |
| Suse | — | Upgrade hostapdUpgrade hostapd-debugsourceUpgrade hostapd-debuginfo | Dec 12, 2013 | Oct 10, 2012 |
| Ubuntu | — | Upgrade hostapd | Nov 19, 2024 | Oct 10, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub