In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later.
Update Linux/Linux to 676a423410131d111a264d29aecbe6aadd57fb22 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanwifi: cfg80211: reject auth/assoc to AP with our address affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=19957bb399e2722719c0e20c9ae91cf8b6aaff04 <676a423410131d111a264d29aecbe6aadd57fb22 || >=19957bb399e2722719c0e20c9ae91cf8b6aaff04 <07added2c6cd63de047bc786b39436322abb67c0 || >=19957bb399e2722719c0e20c9ae91cf8b6aaff04 <5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 |
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later.
Update Linux/Linux to 676a423410131d111a264d29aecbe6aadd57fb22 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanwifi: cfg80211: reject auth/assoc to AP with our address affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=19957bb399e2722719c0e20c9ae91cf8b6aaff04 <676a423410131d111a264d29aecbe6aadd57fb22 || >=19957bb399e2722719c0e20c9ae91cf8b6aaff04 <07added2c6cd63de047bc786b39436322abb67c0 || >=19957bb399e2722719c0e20c9ae91cf8b6aaff04 <5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 |
| 676a423410131d111a264d29aecbe6aadd57fb22, 07added2c6cd63de047bc786b39436322abb67c0, 5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 |
| Linux/Linuxgeneric | 2.6.32 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 676a423410131d111a264d29aecbe6aadd57fb22, 07added2c6cd63de047bc786b39436322abb67c0, 5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 |
| Linux/Linuxgeneric | 2.6.32 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard