The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Netapp
Subscribe
|
8300
Subscribe
8300 Firmware
Subscribe
8700
Subscribe
8700 Firmware
Subscribe
A400
Subscribe
A400 Firmware
Subscribe
A700s
Subscribe
A700s Firmware
Subscribe
Active Iq Unified Manager
Subscribe
Cloud Backup
Subscribe
Data Availability Services
Subscribe
E-series Santricity Os Controller
Subscribe
H610s
Subscribe
H610s Firmware
Subscribe
Hci Management Node
Subscribe
Solidfire
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2114-1 | linux-4.9 security update |
EUVD |
EUVD-2019-8071 | The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:47:14.161Z
Reserved: 2019-10-23T00:00:00
Link: CVE-2019-18282
No data.
Status : Modified
Published: 2020-01-16T16:15:16.950
Modified: 2024-11-21T04:32:58.140
Link: CVE-2019-18282
OpenCVE Enrichment
No data.
Debian DLA
EUVD