Improper input validation in wpa_supplicant - CVE-2018-14526

 

Improper input validation in wpa_supplicant - CVE-2018-14526

Published: August 9, 2018 / Updated: August 9, 2018


Vulnerability identifier: #VU14295
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14526
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists on the systems where WPA2/RSN style of EAPOL-Key construction is used with TKIP negotiated as the pairwise cipher due to an error when processing malicious input. A remote attacker can send specially crafted unauthenticated EAPOL-Key frame data to modify the Group Transient Key (GTK) and prevent the target system from accepting group-addressed frames.


Affected software

wpa_supplicant
busybox (Alpine package)
wpa_supplicant (Alpine package)
wpa_supplicant (Red Hat package)
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Linux kernel
FreeBSD
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
Fedora

How to mitigate CVE-2018-14526

The vendor offers possible mitigation steps:

- Remove TKIP as an allowed pairwise cipher in RSN/WPA2 networks. This
can be done also on the AP side.

- Merge the following commits to wpa_supplicant and rebuild:

WPA: Ignore unauthenticated encrypted EAPOL-Key data

- Update to wpa_supplicant v2.7 or newer, once available.

wpa_supplicant (Alpine package) - update to 2.6-r3
wpa_supplicant (Red Hat package) - update to 2.6-12.el7
wpa_supplicant - addressed in versions 2.6-14.fc27, 2.6-17.fc28
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1

External References

Related Security Bulletins