From patchwork Thu Aug 13 13:39:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10151 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hLRXC4JyVz3wqM for ; Thu, 13 Aug 2026 13:48:27 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hLRX3320jz7QY for ; Thu, 13 Aug 2026 13:48:19 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hLRNQ68tNz377P for ; Thu, 13 Aug 2026 13:41:42 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hLRNF0XpYz2yyM for ; Thu, 13 Aug 2026 13:41:33 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hLRN40YlWz78y; Thu, 13 Aug 2026 13:41:24 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1786628484; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=KK/wkvxbE0npt1j4m4MLst8HiW0mEZAmI97Ld7bbczI=; b=XxjVf0JCeAUCqC7RMltEBLKft994r8rsjgMSgayC6oHbjJja0h4sIA6WaB4ib4RSiffIOD NysixrXFiDmx7vCg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1786628484; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=KK/wkvxbE0npt1j4m4MLst8HiW0mEZAmI97Ld7bbczI=; b=elIqYCaop6WajIUlXyZk+pmAXd9V/mbX7Z2PB2sc31MwjhrxZ3+1pU2byW+durKVyRIrI1 1hhCKrAi+GcAAjBggIpIt1Yi+muRAmTUxAW+tf9Tg46+SJ23wE9cx0PUQCVYJsup4EBITX l9FPz74zrQyUviGr1+RP58VShst+6PKJF0b/UUE+LvPy/Y5uWu/f44RLTjawXTeNwQ60rP 7nxf3VlC87RV8uqalzdSISXmx9ajYk+79CMANKn10CvkmcU7RspY9ZVrKH5W2f6bj5zf/x vN5TWTmY5fhj4OmUQlcOqoW9uYm3wNH59r6dRUhPeggHeD/LYNXA9FxglL0+jg== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] wpa_supplicant: Update to version 2.12 Date: Thu, 13 Aug 2026 15:39:42 +0200 Message-ID: <20260813133942.2669472-13-adolf.belka@ipfire.org> In-Reply-To: <20260813133942.2669472-1-adolf.belka@ipfire.org> References: <20260813133942.2669472-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 2.11 to 2.12 - No change in rootfile - Changelog 2.12 * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * improve BSS transition management support * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks * support Wi-Fi Direct R2 * support Wi-Fi Aware (add synchronized NAN; extend USD support) * support Proximity Ranging * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * enable layer 2/Wi-Fi multicast filtering for all networks (not just some Passpoint networks which enabled this before) * wpa_gui: port to Qt6 * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * maintain configuration file permissions when writing updated configuration * add option to validate PKCS#11/OpenSC engine and module paths * fix PMKSA caching to enforce network context to avoid misuse of unexpected PMKSA cache entries * fix a potential DoS attack in SAE processing of an unexpected element * fix incomplete bounds checking of mesh AMPE messages that could have resulted in DoS attacks and memory corruption * a large number of other fixes, cleanup, and extensions Signed-off-by: Adolf Belka --- lfs/wpa_supplicant | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/lfs/wpa_supplicant b/lfs/wpa_supplicant index 38a147619..e9a2d2c13 100644 --- a/lfs/wpa_supplicant +++ b/lfs/wpa_supplicant @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2025 IPFire Team # +# Copyright (C) 2007-2026 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -24,7 +24,7 @@ include Config -VER = 2.11 +VER = 2.12 THISAPP = wpa_supplicant-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -41,7 +41,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 71bd0d11cd31eb5bc6beb51caf0f1399856ea188f316d2330053a2d8c81869057811e9f500828e8981eabd0af38f30a18a3ae584d744005c78681c82fa910abf +$(DL_FILE)_BLAKE2 = 8a0d4d3d28370fe532676c2d02ce98db3861a6895cb73c83fd33bd3707698ead0bb7b4e9ed5a2cc87ea8db61f75b3da5bf548b67bce45b09223263da01d542ec install : $(TARGET)