CVE-2017-13087 (NVD)

2017-10-17

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

Products Ubuntu_linux, Debian_linux, Freebsd, Leap, Enterprise_linux_desktop, Enterprise_linux_server, Linux_enterprise_desktop, Linux_enterprise_point_of_sale, Linux_enterprise_server, Openstack_cloud, Hostapd, Wpa_supplicant
Type Use of Insufficiently Random Values (CWE-330)
First patch - None (likely due to unavailable code)
Links https://access.redhat.com/security/vulnerabilities/kracks
https://access.redhat.com/errata/RHSA-2017:2907
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html
https://support.lenovo.com/us/en/product_security/LEN-17420
https://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txt