SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant

OPENSUSE-SECURITY-UPDATES <[email protected]>
Newsgroups gmane.linux.suse.security.announce
Message-ID <178586122338.286.1424660811034804712@438c6482d549>
# Security update for wpa_supplicant

Announcement ID: SUSE-SU-2026:3490-1  
Release Date: 2026-08-04T11:58:39Z  
Rating: low  
References:

  * bsc#1239461

  
Cross-References:

  * CVE-2025-24912

  
CVSS scores:

  * CVE-2025-24912 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2025-24912 ( NVD ):  3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

  
Affected Products:

  * openSUSE Leap 15.5
  * SUSE Linux Enterprise Micro 5.5

  
  
An update that solves one vulnerability can now be installed.

## Description:

This update for wpa_supplicant fixes the following issues:

  * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user
    in between the hostapd and the RADIUS server to inject crafted RADIUS
    packets and force RADIUS authentications to fail (bsc#1239461).
  * Missing network context validation for PMKSA caching
    https://w1.fi/security/2026-2/
  * Unexpected SAE commit message contents terminating `wpa_supplicant`
    https://w1.fi/security/2026-3/

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * openSUSE Leap 15.5  
    zypper in -t patch SUSE-2026-3490=1

  * SUSE Linux Enterprise Micro 5.5  
    zypper in -t patch SUSE-SLE-Micro-5.5-2026-3490=1

## Package List:

  * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
    * wpa_supplicant-debugsource-2.10-150500.3.6.1
    * wpa_supplicant-gui-debuginfo-2.10-150500.3.6.1
    * wpa_supplicant-debuginfo-2.10-150500.3.6.1
    * wpa_supplicant-gui-2.10-150500.3.6.1
    * wpa_supplicant-2.10-150500.3.6.1
  * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
    * wpa_supplicant-debuginfo-2.10-150500.3.6.1
    * wpa_supplicant-debugsource-2.10-150500.3.6.1
    * wpa_supplicant-2.10-150500.3.6.1

## References:

  * https://www.suse.com/security/cve/CVE-2025-24912.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1239461
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.