CVE-2026-58374

NameCVE-2026-58374
DescriptionIn hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or Per-STA Profile subelement. In hostapd_process_ml_assoc_req() in src/ap/ieee802_11_eht.c, the received link_id field can be parsed as value 15, but the corresponding links[] storage only has valid entries for lower link IDs (0 through 14). This causes an out-of-bounds write / small memory corruption during association processing before the 4-way handshake. The attack does not require network credentials, prior authentication, or user interaction. The confirmed practical impact is denial of service through hostapd process termination. This affects hostapd v2.11 and newer development snapshots before v2.12 when built with CONFIG_IEEE80211BE enabled. The issue is fixed in hostapd v2.12 and the upstream 2026-1 fixes.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wpa (PTS)bullseye2:2.9.0-21+deb11u2fixed
bullseye (security)2:2.9.0-21+deb11u3fixed
bookworm2:2.10-12+deb12u3fixed
bookworm (security)2:2.10-12+deb12u2fixed
trixie2:2.10-24fixed
forky, sid2:2.10-25fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wpasource(unstable)(not affected)

Notes

- wpa <not-affected> (Vulnerable code not present; EHT/IEEE 802.11be/Wi-Fi 7 support introduced in v2.11)
https://w1.fi/security/2026-1/missing-ml-parsing-validation.txt
https://git.w1.fi/cgit/hostap/commit/?id=46dd5a4ffc9bcf44cf8fc45120b3e1e5ec922187
https://git.w1.fi/cgit/hostap/commit/?id=aa9d345887389a251c63a3781d2ad2940d079193
https://git.w1.fi/cgit/hostap/commit/?id=a8531e3d871e6fa72f2f85d91e9f787326b2af8b
https://git.w1.fi/cgit/hostap/commit/?id=56216d113909650ae59621dc2dd16157afb94948
https://git.w1.fi/cgit/hostap/commit/?id=e4bd3442c2223802bf8c4a4d868e3b9443c7caf4
https://git.w1.fi/cgit/hostap/commit/?id=ce1a8612e309fe86133ecf05ffb452b0bdf3b035
https://git.w1.fi/cgit/hostap/commit/?id=41c86a2ebed50567c73de23c102c2bf83eb883f2
https://git.w1.fi/cgit/hostap/commit/?id=595194d0305189922a057e8ea8b743a1bd8d2d29

Search for package or bug name: Reporting problems