Ubuntu wpa_supplicant Security Update Advisory (CVE-2024-5290)

Overview

Ubuntu has released an update to address a vulnerability in the Ubuntu wpa_supplicant. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-5290

  • Ubuntu 14.04 LTS
  • Ubuntu 16.04 LTS
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 24.04 LTS

 

 

Resolved Vulnerabilities

An issue was discovered in Ubuntu wpa_supplicant loading arbitrary shared objects, which could allow an unprivileged local attacker to escalate privileges to the user running wpa_supplicant (typically root) (CVE-2024-5290)

 

Vulnerability Patches

Vulnerability patches were made available in the latest update as follows Please follow the instructions on the Referenced Sites[2]to update to the latest Vulnerability Patches version.

 

Referenced Sites

[1] CVE-2024-5290 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-5290

[2] USN-6945-1: wpa_supplicant and hostapd vulnerabilities

https://ubuntu.com/security/notices/USN-6945-1