{"id":"UBUNTU-CVE-2019-11555","details":"The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.","modified":"2026-02-04T03:23:19.933061Z","published":"2019-04-26T00:00:00Z","related":["USN-3969-1","USN-3969-2"],"upstream":["CVE-2019-11555"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-11555"},{"type":"REPORT","url":"https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2019/04/26/1"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2019/04/18/6"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-3969-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-3969-2"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2019-11555"}],"affected":[{"package":{"name":"wpa","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/wpa@2.1-0ubuntu1.7+esm1?arch=source&distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1-0ubuntu1.7+esm1"}]}],"versions":["1.0-3ubuntu2","1.0-3ubuntu3","1.0-3ubuntu4","2.1-0ubuntu1","2.1-0ubuntu1.1","2.1-0ubuntu1.2","2.1-0ubuntu1.3","2.1-0ubuntu1.4","2.1-0ubuntu1.5","2.1-0ubuntu1.6","2.1-0ubuntu1.7"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"hostapd","binary_version":"1:2.1-0ubuntu1.7+esm1"},{"binary_name":"wpagui","binary_version":"2.1-0ubuntu1.7+esm1"},{"binary_version":"2.1-0ubuntu1.7+esm1","binary_name":"wpasupplicant"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11555.json"}},{"package":{"name":"wpa","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/wpa@2.4-0ubuntu6.5?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4-0ubuntu6.5"}]}],"versions":["2.4-0ubuntu3","2.4-0ubuntu4","2.4-0ubuntu5","2.4-0ubuntu6","2.4-0ubuntu6.2","2.4-0ubuntu6.3","2.4-0ubuntu6.4"],"ecosystem_specific":{"binaries":[{"binary_name":"hostapd","binary_version":"1:2.4-0ubuntu6.5"},{"binary_name":"wpagui","binary_version":"2.4-0ubuntu6.5"},{"binary_name":"wpasupplicant","binary_version":"2.4-0ubuntu6.5"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11555.json"}},{"package":{"name":"wpa","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/wpa@2:2.6-15ubuntu2.3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.6-15ubuntu2.3"}]}],"versions":["2.4-0ubuntu10","2:2.4-1.1ubuntu1","2:2.6-15ubuntu1","2:2.6-15ubuntu2","2:2.6-15ubuntu2.1","2:2.6-15ubuntu2.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"hostapd","binary_version":"2:2.6-15ubuntu2.3"},{"binary_name":"wpagui","binary_version":"2:2.6-15ubuntu2.3"},{"binary_name":"wpasupplicant","binary_version":"2:2.6-15ubuntu2.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11555.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}