{"id":"AZL-103386","summary":"CVE-2026-78807 affecting package wpa_supplicant 2.10-3","details":"An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c","modified":"2026-09-23T05:36:13Z","published":"2026-09-11T18:16:58Z","upstream":["CVE-2026-78807"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78807"}],"affected":[{"package":{"name":"wpa_supplicant","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/wpa_supplicant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.10-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103386.json"}}],"schema_version":"1.9.0"}