High severity7.5NVD Advisory· Published Apr 17, 2019· Updated Jun 17, 2026
CVE-2019-9496
CVE-2019-9496
Description
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Range: <=2.7
- osv-coords4 versionspkg:rpm/opensuse/hostapd&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/hostapd&distro=openSUSE%20Tumbleweedpkg:rpm/suse/hostapd&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/hostapd&distro=SUSE%20Package%20Hub%2015%20SP1
< 2.9-bp151.5.3.1+ 3 more
- (no CPE)range: < 2.9-bp151.5.3.1
- (no CPE)range: < 2.9-6.2
- (no CPE)range: < 2.9-bp151.5.3.1
- (no CPE)range: < 2.9-bp151.5.3.1
- Range: 2.7
- Wi-Fi Alliance/wpa_supplicant with SAE supportv5Range: 2.7
Patches
Vulnerability mechanics
References
9- w1.fi/security/2019-3/nvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlnvd
- packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/nvd
- seclists.org/bugtraq/2019/May/40nvd
- security.freebsd.org/advisories/FreeBSD-SA-19:03.wpa.ascnvd
- www.synology.com/security/advisory/Synology_SA_19_16nvd
News mentions
0No linked articles in our index yet.