CVE-2019-18282
—CVSS 3.1
5.3 medium
EPSS
3%p84
Published
()
Modified
Description
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
- Vendors
- linuxdebiannetapp
- Products
- linux kernel, debian linux, a700s firmware, 8300 firmware, 8700 firmware, a400 firmware, h610s firmware, active iq unified manager, cloud backup, data availability services, e-series santricity os controller, hci management node
- Weakness
- CWE-330
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.