https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=217907
Update to 2.6. Security vulnerabilities fixed:
- fixed EAP-pwd last fragment validation [http://w1.fi/security/2015-7/] (CVE-2015-5314)
- fixed WPS configuration update vulnerability with malformed passphrase [http://w1.fi/security/2016-1/] (CVE-2016-4476)
Detailed changes can be found here:
https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog