[CLSA-2026:1790639181] hostapd: Fix of CVE-2026-58374
Type:
security
Severity:
Important
Release date:
2026-09-28 23:46:30 UTC
Description:
- CVE-2025-24912: drop a pending RADIUS request from the retransmit list only after a handler has accepted the response, so an injected response with a matching identifier cannot cancel a legitimate pending request
CVEs fixed:
Updated packages:
  • hostapd-2.11-2.el9.tuxcare.els2.aarch64.rpm
    sha:5a982c5a320adeb232c77e82a25ed81856c286f56ee55b0b0bcdf2a46ac7af4d
  • hostapd-2.11-2.el9.tuxcare.els2.i686.rpm
    sha:e1ff6ade51824a071c7b3dec50ec7b2a8cec229c542ff2b029a1952c11b8af5e
  • hostapd-2.11-2.el9.tuxcare.els2.x86_64.rpm
    sha:004238d5d9c20a7c6e084067d65f86aa74fd8a3aaf92b8fe00f874bbffc0d4e2
  • hostapd-logwatch-2.11-2.el9.tuxcare.els2.aarch64.rpm
    sha:366af942a89f018ee288bf09c4df7e101875f05c0f548d17233acbfcb0b6bf6d
  • hostapd-logwatch-2.11-2.el9.tuxcare.els2.i686.rpm
    sha:fb9d77e4297b404624054eb4008c467544a2051f3326974b89bae0f7db02c896
  • hostapd-logwatch-2.11-2.el9.tuxcare.els2.x86_64.rpm
    sha:8a118ccd30e40d41d9d7e7e8e5ca72f204fdef239640b0f75941a2812c90ff78
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.