CVE-2026-58374

Name
CVE-2026-58374
Description
In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or Per-STA Profile subelement. In hostapd_process_ml_assoc_req() in src/ap/ieee802_11_eht.c, the received link_id field can be parsed as value 15, but the corresponding links[] storage only has valid entries for lower link IDs (0 through 14). This causes an out-of-bounds write / small memory corruption during association processing before the 4-way handshake. The attack does not require network credentials, prior authentication, or user interaction. The confirmed practical impact is denial of service through hostapd process termination. This affects hostapd v2.11 and newer development snapshots before v2.12 when built with CONFIG_IEEE80211BE enabled. The issue is fixed in hostapd v2.12 and the upstream 2026-1 fixes.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://git.w1.fi/cgit/hostap/commit/?id=46dd5a4ffc9bcf44cf8fc45120b3e1e5ec922187
Patch https://git.w1.fi/cgit/hostap/commit/?id=aa9d345887389a251c63a3781d2ad2940d079193
Issue Tracking https://w1.fi/security/2026-1/
Mitigation https://w1.fi/security/2026-1/missing-ml-parsing-validation.txt
Mailing List https://www.openwall.com/lists/oss-security/2026/06/30/1

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* hostapd >= None <= 2.11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hostapd edge-main 2.11-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.11-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.11-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.11-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.9-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.9-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.9-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.9-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd edge-main 2.9-r2 None possibly vulnerable
hostapd edge-main 2.9-r1 None possibly vulnerable
hostapd edge-main 2.8-r0 None possibly vulnerable
hostapd edge-main 2.6-r2 None possibly vulnerable
hostapd 3.24-main 2.11-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd 3.23-main 2.11-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd 3.22-main 2.11-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd 3.22-main 2.10-r0 None possibly vulnerable
hostapd 3.22-main 2.9-r3 None possibly vulnerable
hostapd 3.22-main 2.9-r2 None possibly vulnerable
hostapd 3.22-main 2.9-r1 None possibly vulnerable
hostapd 3.22-main 2.8-r0 None possibly vulnerable
hostapd 3.22-main 2.6-r2 None possibly vulnerable
hostapd 3.21-main 2.11-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd 3.21-main 2.10-r0 None possibly vulnerable
hostapd 3.21-main 2.9-r3 None possibly vulnerable
hostapd 3.21-main 2.9-r2 None possibly vulnerable
hostapd 3.21-main 2.9-r1 None possibly vulnerable
hostapd 3.21-main 2.8-r0 None possibly vulnerable
hostapd 3.21-main 2.6-r2 None possibly vulnerable
hostapd 3.20-main 2.10-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd 3.20-main 2.10-r0 None possibly vulnerable
hostapd 3.20-main 2.9-r3 None possibly vulnerable
hostapd 3.20-main 2.9-r2 None possibly vulnerable
hostapd 3.20-main 2.9-r1 None possibly vulnerable
hostapd 3.20-main 2.8-r0 None possibly vulnerable
hostapd 3.20-main 2.6-r2 None possibly vulnerable
hostapd 3.19-main 2.10-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
hostapd 3.19-main 2.10-r0 None possibly vulnerable
hostapd 3.19-main 2.9-r3 None possibly vulnerable
hostapd 3.19-main 2.9-r2 None possibly vulnerable
hostapd 3.19-main 2.9-r1 None possibly vulnerable
hostapd 3.19-main 2.8-r0 None possibly vulnerable
hostapd 3.19-main 2.6-r2 None possibly vulnerable