+++ This bug was initially created as a clone of Bug #23412 +++ Upstream has issued an advisory today (August 8): https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt Patches are available in the same directory and it will be fixed in 2.7. Mageia 6 is also affected. We fixed this for wpa_supplicant, but hostapd is apparently affected too. openSUSE has issued an advisory for this on October 27: https://lists.opensuse.org/opensuse-updates/2018-10/msg00222.html
Whiteboard: (none) => MGA6TOO
Assigning to the registered maintainer.
Assignee: bugsquad => tmbCC: (none) => marja11
I updated it to 2.7 in Cauldron.
Whiteboard: MGA6TOO => (none)Version: Cauldron => 6
Mageia 6 is EOL.
Resolution: (none) => OLDCC: (none) => mramboStatus: NEW => RESOLVED