Oval Definition:oval:com.redhat.rhsa:def:20172907
Revision Date:2017-10-17Version:638
Title:RHSA-2017:2907: wpa_supplicant security update (Important)
Description:The wpa_supplicant packages contain an 802.1X Supplicant with support for WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication methods. They implement key negotiation with a WPA Authenticator for client stations and controls the roaming and IEEE 802.11 authentication and association of the WLAN driver.

Security Fix(es):

  • A new exploitation technique called key reinstallation attacks (KRACK) affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit these attacks to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by manipulating cryptographic handshakes used by the WPA2 protocol. (CVE-2017-13077, CVE-2017-13078, CVE-2017-13080, CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088)

    Red Hat would like to thank CERT for reporting these issues. Upstream acknowledges Mathy Vanhoef (University of Leuven) as the original reporter of these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-13077
    CVE-2017-13078
    CVE-2017-13080
    CVE-2017-13082
    CVE-2017-13086
    CVE-2017-13087
    CVE-2017-13088
    RHSA-2017:2907
    RHSA-2017:2907-00
    RHSA-2017:2907-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND wpa_supplicant is earlier than 1:2.6-5.el7_4.1
  • AND wpa_supplicant is signed with Red Hat redhatrelease2 key
  • BACK