Oval Definition:oval:com.redhat.rhsa:def:20172911
Revision Date:2017-10-18Version:637
Title:RHSA-2017:2911: wpa_supplicant security update (Important)
Description:The wpa_supplicant packages contain an 802.1X Supplicant with support for WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication methods. They implement key negotiation with a WPA Authenticator for client stations and controls the roaming and IEEE 802.11 authentication and association of the WLAN driver.

  • Security Fix(es):
  • A new exploitation technique called key reinstallation attacks (KRACK) affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit these attacks to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by manipulating cryptographic handshakes used by the WPA2 protocol. (CVE-2017-13077, CVE-2017-13078, CVE-2017-13080, CVE-2017-13087)

    Red Hat would like to thank CERT for reporting these issues. Upstream acknowledges Mathy Vanhoef (University of Leuven) as the original reporter of these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-13077
    CVE-2017-13078
    CVE-2017-13080
    CVE-2017-13087
    RHSA-2017:2911
    RHSA-2017:2911-00
    RHSA-2017:2911-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND wpa_supplicant is earlier than 1:0.7.3-9.el6_9.2
  • AND wpa_supplicant is signed with Red Hat redhatrelease2 key
  • BACK