Description
In the Linux kernel, the following vulnerability has been resolved:

inetpeer: randomize RB-tree node comparison using SipHash

The inetpeer rate limiting system stores peer entries in a Red-Black tree
keyed deterministically on the remote IP address. Because tree lookups walk
the RB-tree using standard lexicographical comparisons (inetpeer_addr_cmp),
an off-path adversary can predict the exact topology of the tree and the
sequence of nodes traversed during lookups (the gc_stack candidate list).

By combining deterministic tree traversal with aggressive garbage collection
(triggered when tree size exceeds inet_peer_threshold), an attacker can
selectively force the eviction of targeted inet_peer nodes. When an evicted
node is subsequently re-created upon receiving a new packet, its rate-limiting
token bucket (rate_tokens, rate_last) is reset to full capacity. This creates
a side-channel primitive allowing off-path attackers to bypass IP-keyed ICMP
rate limits and infer open UDP ports (similar to SAD DNS style attacks).

Mitigate this by randomizing the RB-tree node comparison logic using SipHash
with a secret key (inetpeer_hash_key) initialized via net_get_random_once().
Nodes are ordered in the tree by SipHash(addr, key) rather than raw IP
addresses. Because the secret key is unknown to external entities, the tree
layout and lookup traversal paths are unpredictable to off-path adversaries,
breaking the deterministic eviction gadget.

Cache the computed 64-bit SipHash (hash) in struct inet_peer and compute the
target hash (dhash) once at the beginning of inet_getpeer() to avoid recomputing
SipHash at every step of the RB-tree walk.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Side‑channel IP rate‑limit bypass via deterministic eviction
Action: Patch Immediately
AI Analysis

Impact

In the Linux kernel, the inetpeer module historically used a deterministic Red‑Black tree keyed by IP address to store rate‑limiting entries. Because lookups followed a predictable lexicographical comparison, an off‑path attacker could model the tree’s topology and the exact sequence of nodes visited during a lookup. By combining this deterministic traversal with the kernel’s aggressive garbage‑collection threshold (triggered when the tree grows beyond inet_peer_threshold), an attacker could force chosen inet_peer nodes to be evicted. When the evicted node is recreated by a subsequent packet, its token bucket is reset to full capacity, effectively bypassing IP‑keyed ICMP or UDP rate limits and allowing the attacker to derive information such as whether a UDP port is open. This is a side‑channel flaw that can be exploited remotely to circumvent rate limits and conduct port probing.

Affected Systems

The vulnerability affects all Linux kernel versions that implement the unix inetpeer rate‑limiting subsystem without the SipHash‑based randomization patch. The specific vendor is Linux; the affected product is the Linux kernel. No version numbers are listed in the CNA data, so any kernel prior to the full implementation of the described mitigation is potentially affected.

Risk and Exploitability

The CVSS score of 9.4 classifies this flaw as critical, yet the EPSS score of less than 1 % indicates a very low current exploitation probability. The vulnerability is not in the CISA KEV catalog. Attacks would require an off‑path adversary that can send packets to the target host; by sending crafted traffic that targets specific IP addresses, the attacker can trigger the eviction gadget and reset rate‑limiting counters. The lack of a known active exploit at this time suggests that the primary risk lies with the vulnerability’s potential for remote abuse and the side‑channel information disclosure it enables.

Generated by OpenCVE AI on September 20, 2026 at 02:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest kernel that includes the SipHash randomization patch
  • Reboot the affected systems to load the new kernel
  • If the patch cannot be applied immediately, reduce or disable ICMP rate limiting and block excessive inbound UDP traffic to limit the side‑channel’s effectiveness

Generated by OpenCVE AI on September 20, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-917

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using SipHash The inetpeer rate limiting system stores peer entries in a Red-Black tree keyed deterministically on the remote IP address. Because tree lookups walk the RB-tree using standard lexicographical comparisons (inetpeer_addr_cmp), an off-path adversary can predict the exact topology of the tree and the sequence of nodes traversed during lookups (the gc_stack candidate list). By combining deterministic tree traversal with aggressive garbage collection (triggered when tree size exceeds inet_peer_threshold), an attacker can selectively force the eviction of targeted inet_peer nodes. When an evicted node is subsequently re-created upon receiving a new packet, its rate-limiting token bucket (rate_tokens, rate_last) is reset to full capacity. This creates a side-channel primitive allowing off-path attackers to bypass IP-keyed ICMP rate limits and infer open UDP ports (similar to SAD DNS style attacks). Mitigate this by randomizing the RB-tree node comparison logic using SipHash with a secret key (inetpeer_hash_key) initialized via net_get_random_once(). Nodes are ordered in the tree by SipHash(addr, key) rather than raw IP addresses. Because the secret key is unknown to external entities, the tree layout and lookup traversal paths are unpredictable to off-path adversaries, breaking the deterministic eviction gadget. Cache the computed 64-bit SipHash (hash) in struct inet_peer and compute the target hash (dhash) once at the beginning of inet_getpeer() to avoid recomputing SipHash at every step of the RB-tree walk.
Title inetpeer: randomize RB-tree node comparison using SipHash
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:04.902Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90110

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:02.990

Modified: 2026-09-18T18:17:42.327

Link: CVE-2026-90110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-917

    Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')