CVE-2019-13377: Canonical Ubuntu Linux

Medium severity, CVSS 5.9. EPSS: 2.5% chance of exploitation in the next 30 days.

The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 30 only
  • w1.fi Hostapd: from 2.0, up to and including 2.8

Published 2019-08-15. Last modified 2026-06-17.