DEBIAN-CVE-2026-58374

Source
https://security-tracker.debian.org/tracker/CVE-2026-58374
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58374.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-58374
Upstream
Withdrawn
2026-07-02T02:01:31Z
Published
2026-06-30T13:19:18Z
Modified
2026-07-02T02:01:31Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or Per-STA Profile subelement. In hostapd_process_ml_assoc_req() in src/ap/ieee802_11_eht.c, the received link_id field can be parsed as value 15, but the corresponding links[] storage only has valid entries for lower link IDs (0 through 14). This causes an out-of-bounds write / small memory corruption during association processing before the 4-way handshake. The attack does not require network credentials, prior authentication, or user interaction. The confirmed practical impact is denial of service through hostapd process termination. This affects hostapd v2.11 and newer development snapshots before v2.12 when built with CONFIG_IEEE80211BE enabled. The issue is fixed in hostapd v2.12 and the upstream 2026-1 fixes.

References

Affected packages

Debian:11 / wpa

Package

Name
wpa
Purl
pkg:deb/debian/wpa?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2:2.*
2:2.9.0-21
2:2.9.0-21+deb11u1
2:2.9.0-21+deb11u2
2:2.9.0-21+deb11u3
2:2.9.0-22
2:2.9.0-23
2:2.9.0+git20200221+f65da0c-1
2:2.9.0+git20200517+dd2daf0-1
2:2.9.0+git20210909+a75fdcd-1
2:2.9.0+git20211018+2e122945fa53-1
2:2.9.0+git20211116+0b853303ae31-1
2:2.10-1
2:2.10-2
2:2.10-3
2:2.10-4
2:2.10-4exp1
2:2.10-5
2:2.10-6
2:2.10-7
2:2.10-8~bpo11+1
2:2.10-8~bpo11+2
2:2.10-8
2:2.10-9
2:2.10-10
2:2.10-11
2:2.10-12
2:2.10-13
2:2.10-14
2:2.10-15
2:2.10-16
2:2.10-17
2:2.10-18
2:2.10-20
2:2.10-21
2:2.10-21.1
2:2.10-22
2:2.10-23
2:2.10-24
2:2.10-25
2:2.11-1
2:2.11-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58374.json"

Debian:12 / wpa

Package

Name
wpa
Purl
pkg:deb/debian/wpa?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2:2.*
2:2.10-12
2:2.10-12+deb12u1
2:2.10-12+deb12u2
2:2.10-12+deb12u3
2:2.10-13
2:2.10-14
2:2.10-15
2:2.10-16
2:2.10-17
2:2.10-18
2:2.10-20
2:2.10-21
2:2.10-21.1
2:2.10-22
2:2.10-23
2:2.10-24
2:2.10-25
2:2.11-1
2:2.11-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58374.json"

Debian:13 / wpa

Package

Name
wpa
Purl
pkg:deb/debian/wpa?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2:2.*
2:2.10-24
2:2.10-25
2:2.11-1
2:2.11-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58374.json"

Debian:14 / wpa

Package

Name
wpa
Purl
pkg:deb/debian/wpa?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2:2.*
2:2.10-24
2:2.10-25
2:2.11-1
2:2.11-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58374.json"