CVE-2016-4476: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only
- w1.fi Hostapd: from 0.6.7, up to and including 2.5
- w1.fi Wpa Supplicant: from 0.6.7, up to and including 2.5
Published 2016-05-09. Last modified 2026-06-17.