CVE-2019-9494: Fedoraproject Fedora

Medium severity, CVSS 5.9. EPSS: 3.9% chance of exploitation in the next 30 days.

The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

Affected products

  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Freebsd Freebsd: version 11.2 only; version 12.0 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only
  • Synology Radius Server: version 3.0 only
  • Synology Router Manager: before 1.2.3-8087 (fixed in 1.2.3-8087)
  • w1.fi Hostapd: up to and including 2.7
  • w1.fi Wpa Supplicant: up to and including 2.7

Published 2019-04-17. Last modified 2026-06-17.