An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103386.json"