Key management errors in Linux kernel - CVE-2017-13080
Published: October 17, 2017 / Updated: November 11, 2020
Vulnerability identifier: #VU8840
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13080
CWE-ID: CWE-320
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent attacker to force a supplicant to reinstall a previously used group key.
The weakness exists in the processing of the 802.11i 4-way handshake messages of the WPA and WPA2 protocols due to ambiguities in the processing of associated protocol messages. An adjacent attacker can use man-in-the-middle techniques to retransmit previously used message exchanges between supplicant and authenticator.
The vulnerability is dubbed "KRACK" attack.
The weakness exists in the processing of the 802.11i 4-way handshake messages of the WPA and WPA2 protocols due to ambiguities in the processing of associated protocol messages. An adjacent attacker can use man-in-the-middle techniques to retransmit previously used message exchanges between supplicant and authenticator.
The vulnerability is dubbed "KRACK" attack.
Affected software
Linux kernel
Gentoo Linux
Debian Linux
Arch Linux
Microsoft Windows
Apple iOS
FortiOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
ArubaOS (AOS)
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - 4 Year Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
FreeBSD
SUSE Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Junos OS
Slackware Linux
Ubuntu
Opensuse
Windows Server
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Dual Band Wireless-AC 3165
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3168
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 8265
Intel Wireless-AC 9260
Intel Wireless-AC 9461
Intel Wireless-AC 9462
Aironet
Cisco WAP121
Cisco ASA 5506W-X w
Cisco Spark Room Series
Cisco IP Phone 8865
Cisco IP Phone 8861
Cisco DX80 Series IP Phones
Cisco DX70 Series IP Phones
Cisco WAP321
Cisco WAP371
Cisco WAP551
Cisco WAP561
Stratix 5100
Cisco Meraki
Cisco Wireless IP Phone 8821
ESP-IDF
supplicant (Red Hat package)
wpa_supplicant
hostapd
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Gentoo Linux
Debian Linux
Arch Linux
Microsoft Windows
Apple iOS
FortiOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
ArubaOS (AOS)
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - 4 Year Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
FreeBSD
SUSE Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Junos OS
Slackware Linux
Ubuntu
Opensuse
Windows Server
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Dual Band Wireless-AC 3165
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3168
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 8265
Intel Wireless-AC 9260
Intel Wireless-AC 9461
Intel Wireless-AC 9462
Aironet
Cisco WAP121
Cisco ASA 5506W-X w
Cisco Spark Room Series
Cisco IP Phone 8865
Cisco IP Phone 8861
Cisco DX80 Series IP Phones
Cisco DX70 Series IP Phones
Cisco WAP321
Cisco WAP371
Cisco WAP551
Cisco WAP561
Stratix 5100
Cisco Meraki
Cisco Wireless IP Phone 8821
ESP-IDF
supplicant (Red Hat package)
wpa_supplicant
hostapd
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
How to mitigate CVE-2017-13080
Update Linux kernel to version 4.13.14 or 4.9.63.
ESP-IDF - addressed in versions 4.3.5, 5.0.1
supplicant (Red Hat package) - addressed in versions 0.7.3-9.el6_9.2, 2.6-5.el7_4.1
wpa_supplicant - addressed in versions 2.6-3.fc25.1, 2.6-11.fc26, 2.6-11.fc27
hostapd - addressed in versions 2.6-6.fc25, 2.6-6.fc26, 2.6-6.fc27, 2.6-7.el6, 2.6-7.el7
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
supplicant (Red Hat package) - addressed in versions 0.7.3-9.el6_9.2, 2.6-5.el7_4.1
wpa_supplicant - addressed in versions 2.6-3.fc25.1, 2.6-11.fc26, 2.6-11.fc27
hostapd - addressed in versions 2.6-6.fc25, 2.6-6.fc26, 2.6-6.fc27, 2.6-7.el6, 2.6-7.el7
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
External References
Related Security Bulletins
- Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II in Cisco products
- Man-in-the-middle in Microsoft Windows WPA/WPA2 Protocol
- Multiple vulnerabilities in Juniper Junos SRX Series WPA/WPA2 Protocol
- Multiple vulnerabilities in Fortinet FortiOS WPA/WPA2 Protocol
- Multiple vulnerabilities ArubaOS WPA/WPA2 Protocol
- FreeBSD update for WPA2 protocol
- Debian update for wpa
- Ubuntu update for wpa_supplicant and hostapd
- Arch Linux update for hostapd
- [ASA-201710-22] wpa_supplicant: man-in-the-middle
- Slackware Linux update for wpa_supplicant
- Multiple vulnerabilities in Rockwell Automation Stratix 5100
- Multiple vulnerabilities in Apple iOS
- Gentoo update for hostapd and wpa_supplicant
- KRACK attack in Linux kernel
- SUSE Linux update for kernel-firmware
- Ubuntu update for Linux firmware
- Multiple vulnerabilities in Apple iOS
- OpenSUSE Linux update for wpa
- SUSE Linux update for wpa
- SUSE Linux update for wpa
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for kernel-firmware
- OpenSUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for hostapd
- Multiple vulnerabilities in Intel PROSet/Wireless WiFi products
- Multiple vulnerabilities in ESP-IDF
- SUSE update for wpa_supplicant
- Multiple vulnerabilities in ESP-IDF
- Fedora 26 update for wpa_supplicant
- Fedora 25 update for wpa_supplicant
- Fedora 27 update for wpa_supplicant
- Fedora EPEL 7 update for hostapd
- Fedora EPEL 6 update for hostapd
- Fedora 26 update for hostapd
- Fedora 25 update for hostapd
- Fedora 27 update for hostapd
- Red Hat Enterprise Linux 7 update for wpa_supplicant
- Red Hat Enterprise Linux 6 update for wpa_supplicant