CVE-2016-4476: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only
  • w1.fi Hostapd: from 0.6.7, up to and including 2.5
  • w1.fi Wpa Supplicant: from 0.6.7, up to and including 2.5

Published 2016-05-09. Last modified 2026-06-17.