CVE-2015-4142: Opensuse

Medium severity, CVSS 4.3. EPSS: 4.2% chance of exploitation in the next 30 days.

Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.

Affected products

  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • w1.fi Hostapd: version 0.7.0 only; version 0.7.1 only; version 0.7.2 only; version 0.7.3 only; version 1.0 only; version 1.1 only; …
  • w1.fi Wpa Supplicant: version 0.7.0 only; version 0.7.1 only; version 0.7.2 only; version 0.7.3 only; version 1.0 only; version 1.1 only; …

Published 2015-06-15. Last modified 2026-06-17.