openwrt-pf/package/network/services
Hauke Mehrtens 8614a2ba68 hostapd: fix security advisory 2026-1
Cherry pick the patches recommended in the hostapd security advisory
2026-1:
https://w1.fi/security/2026-1/missing-ml-parsing-validation.txt

Vulnerability

Vulnerabilities in parsing and use of received multi-link (MLO/EHT/IEEE
802.11be/Wi-Fi 7) information has been identified in hostapd and
wpa_supplicant. These issues show up in various cases where frames
including information on affiliated links are parsed and processed in
both AP and STA modes. The issues can result in process termination due
to buffer read overflow checks and memory corruption.

The issues for AP mode (hostapd or wpa_supplicant) can result in
denial-of-service attacks due to process termination and small memory
corruption that could theoretically cause other issues, but it does not
seem likely that those could be exploiting in practice. Affected areas
can be reached by sending invalid Management frames without needing
authentication or user action on the target device.

CVE-2026-58374

Link: https://github.com/openwrt/openwrt/pull/24043
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2026-07-05 01:20:15 +02:00
..
bridger bridger: update to Git HEAD (2026-03-23) 2026-03-23 10:57:16 +01:00
dnsmasq Revert "dnsmasq: migrate dhcpv4/dhcpv6 default on upgrade" 2026-07-04 13:28:46 +02:00
dropbear dropbear: rework failsafe script 2026-05-28 01:19:35 +02:00
ead ead: Increase PKG_RELEASE 2026-07-01 23:09:23 +02:00
hostapd hostapd: fix security advisory 2026-1 2026-07-05 01:20:15 +02:00
ipset-dns treewide: switch to HTTPS URL 2026-01-02 18:07:02 +01:00
lldpd lldpd: resolve bridge VLAN sub-interfaces to member ports 2026-06-24 11:21:28 +02:00
odhcpd odhcpd: update to Git HEAD (2026-06-28) 2026-06-28 00:46:48 +02:00
omcproxy omcproxy: update to Git HEAD (2026-03-07) 2026-03-08 08:23:20 +01:00
ppp ppp: update to 2.5.3 2026-06-13 01:34:23 +02:00
relayd
uhttpd uhttpd: update to Git HEAD (2026-06-16) 2026-06-16 01:39:53 +02:00
umdns umdns: update to Git HEAD (2026-06-27) 2026-06-27 17:30:10 +02:00
unetd unetd: cli: convey network name from inviter to joiner 2026-06-03 11:19:06 +00:00
unetmsg unetmsg: notify subscribers when remote peer connection drops 2026-02-07 10:04:18 +01:00
ustp ustp: update to Git HEAD (2026-05-27) 2026-05-27 14:32:21 +03:00