openwrt/package
Rany Hany db7f70fe61 hostapd: fix SAE H2E security vulnerability
This patch backports fixes for a security vulnerability impacting the
hostapd implementation of SAE H2E.

As upgrading hostapd would require more testing, the second mitigation
step which involves backporting several patches was adopted as outlined
in the official advisory[1].

An explanation of the impact of the vulnerability is provided from the
advisory[1]:

This vulnerability allows the attacker to downgrade the negotiated group
to another enabled group if both the AP and STA have enabled SAE H2E and
multiple groups. It should be noted that the H2E option is not enabled
by default and the attack is not applicable to the default option, i.e.,
hunting-and-pecking, since it does not have any downgrade protection for
group negotiation. In addition, the default configuration for enabled
SAE groups in hostapd is to enable only a single group, so the
vulnerability is not applicable unless hostapd has been explicitly
configured to enable more groups for SAE.

[1]: https://w1.fi/security/2024-2/sae-h2h-and-incomplete-downgrade-protection-for-group-negotiation.txt

Signed-off-by: Rany Hany <rany_hany@riseup.net>
Link: https://github.com/openwrt/openwrt/pull/16042
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2024-08-02 23:13:44 +02:00
..
base-files base-files: upgrade: nand: allow custom fw extraction in nand_do_upgrade() 2024-07-26 13:41:25 +02:00
boot kobs-ng: Mark as nonshared to build in step 1 2024-07-30 21:42:33 +02:00
devel ply: add dynamic tracing package using BPF 2024-05-31 11:51:45 +02:00
firmware firmware: Add CZ.NIC Turris Omnia MCU firmware 2024-08-02 22:11:05 +02:00
kernel gpio-button-hotplug: add vendor button handling 2024-08-02 22:11:05 +02:00
libs ncurses: Fix path in ncursesw.pc 2024-07-28 19:30:35 +02:00
network hostapd: fix SAE H2E security vulnerability 2024-08-02 23:13:44 +02:00
system fstools: update to git HEAD 2024-07-14 19:45:21 +01:00
utils utils: Add the omnia-mcutool utility 2024-08-02 22:11:05 +02:00
Makefile build: package: fix missing host apk dependency 2024-06-11 23:58:14 +02:00