---
id: CVE-2022-23304
title: >-
  The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant
  before 2.10 are vulnerable to side-channel attacks as a result of cache access
  patterns
summary: >-
  The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant
  before 2.10 are vulnerable to side-channel attacks as a result of cache access
  patterns. NOTE: this issue exists because of an incomplete fix for
  CVE-2019-9495.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-203
vendor: w1.fi
product: hostapd
affected:
  - hostapd < 2.10
  - wpa_supplicant < 2.10
  - fedora = 35
patched:
  - hostapd 2.10
  - wpa_supplicant 2.10
published: '2022-01-17'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23304'
references:
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPDHU5MV464CZBPX7N2SNMUYP6DFIBZL/
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202309-16'
    label: cve@mitre.org
  - url: 'https://w1.fi/security/2022-1/'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2025/04/msg00019.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPDHU5MV464CZBPX7N2SNMUYP6DFIBZL/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202309-16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://w1.fi/security/2022-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-585531.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.01903
epssPercentile: 0.78825
ingestedAt: '2026-07-14T12:36:47.700Z'
---

## Overview

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

## Affected

- `hostapd < 2.10`
- `wpa_supplicant < 2.10`
- `fedora = 35`

## Remediation

Upgrade past the affected range:

- `hostapd 2.10`
- `wpa_supplicant 2.10`
