Loading HuntDB...

GHSA-cvqc-p7v4-m9pm

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

Related CVEs

Key Information

GHSA ID
GHSA-cvqc-p7v4-m9pm
Published
May 13, 2022 1:05 AM
Last Modified
May 13, 2022 1:05 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.