Hi, The following vulnerability was published for wpa. CVE-2026-78807[0]: | An issue in wpa_supplicant all versions before v.2.12 allows a local | attacker to bypass proper network context and AKMP matching for | PMKSA caching via missing validation in the driver based PMKSA | selection path in wpa.c If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-78807 https://www.cve.org/CVERecord?id=CVE-2026-78807 [1] https://w1.fi/security/2026-2/missing-network-context-validation-for-pmksa-caching.txt [2] https://git.w1.fi/cgit/hostap/commit/?id=de5e73a03c34d83568afb3183b2b28c8d7641a30 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Dear maintainer, I've prepared an NMU for wpa (versioned as 2:2.10-25.1) but I have not yet uploaded it to any delayed queue, will follow up later on this (and doing the same changes for trixie). Here is already the proposed debdiff. Regards, Salvatore