CVE-2019-13377: Canonical Ubuntu Linux
Medium severity, CVSS 5.9. EPSS: 2.5% chance of exploitation in the next 30 days.
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 30 only
- w1.fi Hostapd: from 2.0, up to and including 2.8
Published 2019-08-15. Last modified 2026-06-17.