CVE-2013-4579

medium
Published 2013-11-20 Β· Modified 2026-04-29
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.3

Description

The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses with certain bit manipulations.

Predictions

Exploit likelihood
55%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2013-4579 NameCVE-2013-4579 DescriptionThe ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses…

CVE-2013-4579

NameCVE-2013-4579
DescriptionThe ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses with certain bit manipulations.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs729573

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.257-1fixed
bookworm6.1.170-3fixed
bookworm (security)6.1.174-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.90-2fixed
forky7.0.9-1fixed
sid7.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcewheezy3.2.54-1
linuxsource(unstable)3.12.8-1729573
linux-2.6source(unstable)(not affected)

Notes

- linux-2.6 <not-affected> (ath9k not yet present)
http://www.mathyvanhoef.com/2013/11/unmasking-spoofed-mac-address.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- linux-2.6 <not-affected> (ath9k not yet present)http://www.mathyvanhoef.com/2013/11/unmasking-spoofed-mac-address.html

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-38826 remote linux verified
Mathy Vanhoef Β· 2013-12-10

Linux Kernel 3.0.5 - 'ath9k_htc_set_bssid_mask()' Information Disclosure

Source code queued for fetch β€” refresh in a moment.

OS impact

linux Linux kernel Affected 195 releases
VersionStatusFixed in
3.8.10 Affected β€”
3.8.9 Affected β€”
3.8.8 Affected β€”
3.8.7 Affected β€”
3.8.6 Affected β€”
3.8.5 Affected β€”
3.8.4 Affected β€”
3.8.3 Affected β€”
3.8.2 Affected β€”
3.8.1 Affected β€”
3.8.0 Affected β€”
3.7.10 Affected β€”
3.7.9 Affected β€”
3.7.8 Affected β€”
3.7.7 Affected β€”
3.7.6 Affected β€”
3.7.5 Affected β€”
3.7.4 Affected β€”
3.7.3 Affected β€”
3.7.2 Affected β€”
3.7.1 Affected β€”
3.7 Affected β€”
3.6.11 Affected β€”
3.6.10 Affected β€”
3.6.9 Affected β€”
3.6.8 Affected β€”
3.6.7 Affected β€”
3.6.6 Affected β€”
3.6.5 Affected β€”
3.6.4 Affected β€”
3.6.3 Affected β€”
3.6.2 Affected β€”
3.6.1 Affected β€”
3.6 Affected β€”
3.5.7 Affected β€”
3.5.6 Affected β€”
3.5.5 Affected β€”
3.5.4 Affected β€”
3.5.3 Affected β€”
3.5.2 Affected β€”
3.5.1 Affected β€”
3.4.32 Affected β€”
3.4.31 Affected β€”
3.4.30 Affected β€”
3.4.29 Affected β€”
3.4.28 Affected β€”
3.4.27 Affected β€”
3.4.26 Affected β€”
3.4.25 Affected β€”
3.4.24 Affected β€”
3.4.23 Affected β€”
3.4.22 Affected β€”
3.4.21 Affected β€”
3.4.20 Affected β€”
3.4.19 Affected β€”
3.4.18 Affected β€”
3.4.17 Affected β€”
3.4.16 Affected β€”
3.4.15 Affected β€”
3.4.14 Affected β€”
3.4.13 Affected β€”
3.4.12 Affected β€”
3.4.11 Affected β€”
3.4.10 Affected β€”
3.4.9 Affected β€”
3.4.8 Affected β€”
3.4.7 Affected β€”
3.4.6 Affected β€”
3.4.5 Affected β€”
3.4.4 Affected β€”
3.4.3 Affected β€”
3.4.2 Affected β€”
3.4.1 Affected β€”
3.4 Affected β€”
3.3.8 Affected β€”
3.3.7 Affected β€”
3.3.6 Affected β€”
3.3.5 Affected β€”
3.3.4 Affected β€”
3.3.3 Affected β€”
3.3.2 Affected β€”
3.3.1 Affected β€”
3.3 Affected β€”
3.2.30 Affected β€”
3.2.29 Affected β€”
3.2.28 Affected β€”
3.2.27 Affected β€”
3.2.26 Affected β€”
3.2.25 Affected β€”
3.2.24 Affected β€”
3.2.23 Affected β€”
3.2.22 Affected β€”
3.2.21 Affected β€”
3.2.20 Affected β€”
3.2.19 Affected β€”
3.2.18 Affected β€”
3.2.17 Affected β€”
3.2.16 Affected β€”
3.2.15 Affected β€”
3.2.14 Affected β€”
3.2.13 Affected β€”
3.2.12 Affected β€”
3.2.11 Affected β€”
3.2.10 Affected β€”
3.2.9 Affected β€”
3.2.8 Affected β€”
3.2.7 Affected β€”
3.2.6 Affected β€”
3.2.5 Affected β€”
3.2.4 Affected β€”
3.2.3 Affected β€”
3.2.2 Affected β€”
3.2.1 Affected β€”
3.2 Affected β€”
3.1.10 Affected β€”
3.1.9 Affected β€”
3.1.8 Affected β€”
3.1.7 Affected β€”
3.1.6 Affected β€”
3.1.5 Affected β€”
3.1.4 Affected β€”
3.1.3 Affected β€”
3.1.2 Affected β€”
3.1.1 Affected β€”
3.1 Affected β€”
3.0.68 Affected β€”
3.0.67 Affected β€”
3.0.66 Affected β€”
3.0.65 Affected β€”
3.0.64 Affected β€”
3.0.63 Affected β€”
3.0.62 Affected β€”
3.0.61 Affected β€”
3.0.60 Affected β€”
3.0.59 Affected β€”
3.0.58 Affected β€”
3.0.57 Affected β€”
3.0.56 Affected β€”
3.0.55 Affected β€”
3.0.54 Affected β€”
3.0.53 Affected β€”
3.0.52 Affected β€”
3.0.51 Affected β€”
3.0.50 Affected β€”
3.0.49 Affected β€”
3.0.48 Affected β€”
3.0.47 Affected β€”
3.0.46 Affected β€”
3.0.45 Affected β€”
3.0.44 Affected β€”
3.0.43 Affected β€”
3.0.42 Affected β€”
3.0.41 Affected β€”
3.0.40 Affected β€”
3.0.39 Affected β€”
3.0.38 Affected β€”
3.0.37 Affected β€”
3.0.36 Affected β€”
3.0.35 Affected β€”
3.0.34 Affected β€”
3.0.33 Affected β€”
3.0.32 Affected β€”
3.0.31 Affected β€”
3.0.30 Affected β€”
3.0.29 Affected β€”
3.0.28 Affected β€”
3.0.27 Affected β€”
3.0.26 Affected β€”
3.0.25 Affected β€”
3.0.24 Affected β€”
3.0.23 Affected β€”
3.0.22 Affected β€”
3.0.21 Affected β€”
3.0.20 Affected β€”
3.0.19 Affected β€”
3.0.18 Affected β€”
3.0.17 Affected β€”
3.0.16 Affected β€”
3.0.15 Affected β€”
3.0.14 Affected β€”
3.0.13 Affected β€”
3.0.12 Affected β€”
3.0.11 Affected β€”
3.0.10 Affected β€”
3.0.9 Affected β€”
3.0.8 Affected β€”
3.0.7 Affected β€”
3.0.6 Affected β€”
3.0.5 Affected β€”
3.0.4 Affected β€”
3.0.3 Affected β€”
3.0.2 Affected β€”
3.0.1 Affected β€”
3.0 Affected β€”
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.12.8-1
sid Fixed 3.12.8-1
forky Fixed 3.12.8-1
bullseye Fixed 3.12.8-1
bookworm Fixed 3.12.8-1

References

CWEs

CWE-310

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.