Vulnerability Name: | CVE-2022-32296 (CCN-228178) | ||||||||||||||||||||||||
Assigned: | 2022-05-04 | ||||||||||||||||||||||||
Published: | 2022-05-04 | ||||||||||||||||||||||||
Updated: | 2022-09-28 | ||||||||||||||||||||||||
Summary: | The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056. | ||||||||||||||||||||||||
CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-203 | ||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-32296 Source: MISC Type: UNKNOWN https://arxiv.org/abs/2209.12993 Source: MISC Type: Release Notes, Vendor Advisory https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.9 Source: XF Type: UNKNOWN linux-kernel-cve202232296-info-disc(228178) Source: MISC Type: Mailing List, Patch, Vendor Advisory https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4c2c8f03a5ab7cb04ec64724d7d176d00bcc91e5 Source: CCN Type: Linux Kernel GIT Repository tcp: increase source port perturb table to 2 16 Source: MISC Type: UNKNOWN https://github.com/0xkol/rfc6056-device-tracker Source: MLIST Type: UNKNOWN [debian-lts-announce] 20220701 [SECURITY] [DLA 3065-1] linux security update Source: DEBIAN Type: UNKNOWN DSA-5173 Source: CCN Type: IBM Security Bulletin 6847563 (Elastic Storage System) Multiple Linux Kernel vulnerabilities may affect IBM Elastic Storage System | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |