Release of hostapd and wpa_supplicant 2.10

After a year and a half of development, the release of hostapd/wpa_supplicant 2.10 has been prepared, a set for supporting wireless protocols IEEE 802.1X, WPA, WPA2, WPA3, and EAP, consisting of the wpa_supplicant application for connecting to a wireless network as a client and the background process hostapd for ensuring the operation of access points and authentication servers, including components such as WPA Authenticator, RADIUS authentication client/server, and EAP server. The source code of the project is distributed under the BSD license.

In addition to functional changes in the new version, a new attack vector via side channels has been blocked, affecting the SAE (Simultaneous Authentication of Equals) connection negotiation method and the EAP-pwd protocol. An attacker capable of executing unprivileged code on the user's system connecting to a wireless network can obtain information regarding password characteristics through system activity tracking and use this information to simplify offline password cracking. The problem arises from side-channel leaks of password characteristics that allow for indirect data, such as variations in operation delays, to refine the correctness of password segment selection during the cracking process.

Unlike similar issues resolved in 2019, the new vulnerability arises from the fact that external cryptographic primitives used in the crypto_ec_point_solve_y_coord() function did not provide constant time execution for operations, independent of the nature of the data being processed. Based on cache behavior analysis, an attacker with the ability to run unprivileged code on the same CPU core could extract information about the password operation execution flow in SAE/EAP-pwd. All versions of wpa_supplicant and hostapd built with support for SAE (CONFIG_SAE=y) and EAP-pwd (CONFIG_EAP_PWD=y) are affected by this issue.

Other changes in the new releases of hostapd and wpa_supplicant:

  • Added the ability to build with the OpenSSL 3.0 cryptographic library.
  • Implemented the Beacon Protection mechanism proposed in the WPA3 specification update, designed to protect against active attacks on wireless networks that manipulate Beacon frame alterations.
  • Support for the DPP 2 protocol (Wi-Fi Device Provisioning Protocol) has been added, which defines a method of authentication via public keys used in the WPA3 standard for simplified device setup without a screen interface. Configuration is performed using another more advanced device already connected to the wireless network. For example, parameters for a screenless IoT device can be set from a smartphone based on a QR code printed on the device's casing.
  • Support for Extended Key ID (IEEE 802.11-2016) has been added.
  • Support for the SAE-PK (SAE Public Key) protection mechanism has been added to the SAE connection negotiation method. An instant confirmation sending mode can be enabled with the option 'sae_config_immediate=1', as well as a hash-to-element mechanism activated by setting the parameter 'sae_pwe' to 1 or 2.
  • Support for TLS 1.3 has been added to EAP-TLS (disabled by default).
  • New settings (max_auth_rounds, max_auth_rounds_short) have been added to modify the limits on the number of EAP messages during authentication (limit modifications may be necessary when using very large certificates).
  • Support for the PASN (Pre Association Security Negotiation) mechanism has been added to establish a secure connection and protect control frame exchanges at an earlier stage of connection.
  • The Transition Disable mechanism has been implemented, which allows for enhancing security by automatically disabling roaming mode that permits handoffs between access points while moving.
  • Support for the WEP protocol has been removed from default builds (to restore WEP support, a rebuild with the CONFIG_WEP=y option is required). Deprecated functionality related to the IAPP (Inter-Access Point Protocol) has been removed. Support for libnl 1.1 has been discontinued. A build option CONFIG_NO_TKIP=y has been added for building without TKIP support.
  • Vulnerabilities in the UPnP implementation (CVE-2020-12695), in the P2P/Wi-Fi Direct handler (CVE-2021-27803), and in the PMF protection mechanism (CVE-2019-16275) have been fixed.
  • Notable changes specific to hostapd include an expanded support for HEW (High-Efficiency Wireless, IEEE 802.11ax) wireless networks, including the ability to use the 6 GHz frequency band.
  • Changes specific to wpa_supplicant:
    • Support for access point mode settings for SAE (WPA3-Personal) has been added.
    • Support for P2P mode has been implemented for EDMG channels (IEEE 802.11ay).
    • Improved capacity forecasting and BSS selection.
    • Expanded management interface via D-Bus.
    • A new backend has been added for storing passwords in a separate file, allowing confidential information to be extracted from the main configuration file.
    • New policies have been added for SCS, MSCS, and DSCP.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster