CVE-2017-13082: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 4.6% chance of exploitation in the next 30 days.

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Freebsd Freebsd: any version; version 10 only; version 10.4 only; version 11 only; version 11.1 only
  • Opensuse Leap: version 42.2 only; version 42.3 only
  • Red Hat Enterprise Linux Desktop: version 7 only
  • Red Hat Enterprise Linux Server: version 7 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Point Of Sale: version 11 only
  • Suse Linux Enterprise Server: version 11 only; version 12 only
  • Suse Openstack Cloud: version 6 only
  • w1.fi Hostapd: version 0.2.4 only; version 0.2.5 only; version 0.2.6 only; version 0.2.8 only; version 0.3.7 only; version 0.3.9 only; …
  • w1.fi Wpa Supplicant: version 0.2.4 only; version 0.2.5 only; version 0.2.6 only; version 0.2.7 only; version 0.2.8 only; version 0.3.7 only; …

Published 2017-10-17. Last modified 2026-06-17.