Re: [oe] [PATCH] [OE-devel] [meta-openembedded] hostapd: fix CVE-2021-30004

2021-04-08 Thread Khem Raj
Thanks for your contributioin Stefan, unfortunately this patch is not application on master, can you rebase and send again ? On 4/8/21 9:44 AM, Stefan Ghinea wrote: In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c

[oe] [PATCH] [OE-devel] [meta-openembedded] hostapd: fix CVE-2021-30004

2021-04-08 Thread Stefan Ghinea
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c. References: https://nvd.nist.gov/vuln/detail/CVE-2021-30004 Upstream patches: