Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: NixOS/nixpkgs
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 1cdb903086f8
Choose a base ref
...
head repository: NixOS/nixpkgs
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 5450e23dd06e
Choose a head ref
  • 2 commits
  • 1 file changed
  • 2 contributors

Commits on Apr 25, 2020

  1. hostapd: apply patch for CVE-2019-16275

    AP mode PMF disconnection protection bypass
    
    Published: September 11, 2019
    Identifiers:
    - CVE-2019-16275
    Latest version available from: https://w1.fi/security/2019-7/
    
    Vulnerability
    
    hostapd (and wpa_supplicant when controlling AP mode) did not perform
    sufficient source address validation for some received Management frames
    and this could result in ending up sending a frame that caused
    associated stations to incorrectly believe they were disconnected from
    the network even if management frame protection (also known as PMF) was
    negotiated for the association. This could be considered to be a denial
    of service vulnerability since PMF is supposed to protect from this type
    of issues. It should be noted that if PMF is not enabled, there would be
    no protocol level protection against this type of denial service
    attacks.
    
    An attacker in radio range of the access point could inject a specially
    constructed unauthenticated IEEE 802.11 frame to the access point to
    cause associated stations to be disconnected and require a reconnection
    to the network.
    
    Vulnerable versions/configurations
    
    All hostapd and wpa_supplicants versions with PMF support
    (CONFIG_IEEE80211W=y) and a runtime configuration enabled AP mode with
    PMF being enabled (optional or required). In addition, this would be
    applicable only when using user space based MLME/SME in AP mode, i.e.,
    when hostapd (or wpa_supplicant when controlling AP mode) would process
    authentication and association management frames. This condition would
    be applicable mainly with drivers that use mac80211.
    
    Possible mitigation steps
    
    - Merge the following commit to wpa_supplicant/hostapd and rebuild:
    
      AP: Silently ignore management frame from unexpected source address
    
      This patch is available from https://w1.fi/security/2019-7/
    
    - Update to wpa_supplicant/hostapd v2.10 or newer, once available
    
    (cherry picked from commit 3e9f3a3)
    mweinelt committed Apr 25, 2020

    Unverified

    This commit is not signed, but one or more authors requires that any commit attributed to them is signed.
    Copy the full SHA
    356c899 View commit details
  2. Merge pull request #86000 from mweinelt/20.03/hostapd/cve-2019-16275

    [20.03] hostapd: apply patch for CVE-2019-16275
    worldofpeace authored Apr 25, 2020

    Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
    Copy the full SHA
    5450e23 View commit details
Showing with 7 additions and 1 deletion.
  1. +7 −1 pkgs/os-specific/linux/hostapd/default.nix
8 changes: 7 additions & 1 deletion pkgs/os-specific/linux/hostapd/default.nix
Original file line number Diff line number Diff line change
@@ -17,7 +17,13 @@ stdenv.mkDerivation rec {
# Note: fetchurl seems to be unhappy with openwrt git
# server's URLs containing semicolons. Using the github mirror instead.
url = "https://raw.githubusercontent.com/openwrt/openwrt/master/package/network/services/hostapd/patches/300-noscan.patch";
sha256 = "04wg4yjc19wmwk6gia067z99gzzk9jacnwxh5wyia7k5wg71yj5k";})
sha256 = "04wg4yjc19wmwk6gia067z99gzzk9jacnwxh5wyia7k5wg71yj5k";
})
(fetchurl {
name = "CVE-2019-16275.patch";
url = "https://w1.fi/security/2019-7/0001-AP-Silently-ignore-management-frame-from-unexpected-.patch";
sha256 = "15xjyy7crb557wxpx898b5lnyblxghlij0xby5lmj9hpwwss34dz";
})
];

outputs = [ "out" "man" ];