---
title: "CVE-2019-5061\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-5061?format=md
keywords: index, follow
---

# CVE-2019-5061

Publication date 12 December 2019

Last updated 26 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.4 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2019-5061?format=md#impact-score)

Toggle side navigation

## Description

An exploitable denial-of-service vulnerability exists in the hostapd 2.6,
where an attacker could trigger AP to send IAPP location updates for
stations, before the required authentication process has completed. This
could lead to different denial of service scenarios, either by causing CAM
table attacks, or by leading to traffic flapping if faking already existing
clients in other nearby Aps of the same wireless infrastructure. An
attacker can forge Authentication and Association Request packets to
trigger this vulnerability.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-5061?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| wpa | 26.04 LTS resolute | Fixed 2:2.9.0-20build1 |
| 25.10 questing | Fixed 2:2.9.0-20build1 |
| 25.04 plucky | Fixed 2:2.9.0-20build1 |
| 24.10 oracular | Fixed 2:2.9.0-20build1 |
| 24.04 LTS noble | Fixed 2:2.9.0-20build1 |
| 23.10 mantic | Fixed 2:2.9.0-20build1 |
| 23.04 lunar | Fixed 2:2.9.0-20build1 |
| 22.10 kinetic | Fixed 2:2.9.0-20build1 |
| 22.04 LTS jammy | Fixed 2:2.9.0-20build1 |
| 21.10 impish | Fixed 2:2.9.0-20build1 |
| 21.04 hirsute | Fixed 2:2.9.0-20build1 |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Needs evaluation |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-5061?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

upstream fix appears to be to remove (the incomplete) IAPP support completely.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| wpa | * Upstream:   [?id=018](https://w1.fi/cgit/hostap/commit/?id=018edec9b2bd3db20605117c32ff79c1e625c432) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.4 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Adjacent |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.4 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5061)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-5061)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-5061)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-5061)

### Other references

* <https://talosintelligence.com/vulnerability_reports/TALOS-2019-0849>
* <https://www.cve.org/CVERecord?id=CVE-2019-5061>
