CVE-2019-9494: Fedoraproject Fedora
Medium severity, CVSS 5.9. EPSS: 3.9% chance of exploitation in the next 30 days.
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
Affected products
- Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
- Freebsd Freebsd: version 11.2 only; version 12.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only
- Synology Radius Server: version 3.0 only
- Synology Router Manager: before 1.2.3-8087 (fixed in 1.2.3-8087)
- w1.fi Hostapd: up to and including 2.7
- w1.fi Wpa Supplicant: up to and including 2.7
Published 2019-04-17. Last modified 2026-06-17.