CVE-2019-16275: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 8.0 only; version 10.0 only
- w1.fi Hostapd: up to and including 2.9
- w1.fi Wpa Supplicant: up to and including 2.9
Published 2019-09-12. Last modified 2026-06-17.