Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78807

Опубликовано: 11 сент. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

A flaw was found in wpa_supplicant. A local attacker can exploit missing validation in the driver-based PMKSA (Pairwise Master Key Security Association) selection path to bypass proper network context and AKMP (Authentication Key Management Protocol) matching for PMKSA caching. This could allow the attacker to gain unauthorized access to cached network credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wpa_supplicantAffected
Red Hat Enterprise Linux 6wpa_supplicantOut of support scope
Red Hat Enterprise Linux 7wpa_supplicantAffected
Red Hat Enterprise Linux 8wpa_supplicantAffected
Red Hat Enterprise Linux 9wpa_supplicantAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-322
https://bugzilla.redhat.com/show_bug.cgi?id=2531997wpa_supplicant: wpa_supplicant: Security bypass via missing PMKSA validation

EPSS

Процентиль: 0%
0.0008
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
6 дней назад

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

CVSS3: 7.1
nvd
6 дней назад

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

CVSS3: 7.1
debian
6 дней назад

An issue in wpa_supplicant all versions before v.2.12 allows a local a ...

CVSS3: 7.1
github
6 дней назад

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

EPSS

Процентиль: 0%
0.0008
Низкий

7.1 High

CVSS3