Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-32296

Опубликовано: 05 мая 2022
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

Отчет

This flaw was found to be a duplicate of CVE-2022-1012. Please see https://access.redhat.com/security/cve/CVE-2022-1012 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelUnder investigation
Red Hat Enterprise Linux 7kernelUnder investigation
Red Hat Enterprise Linux 7kernel-rtUnder investigation
Red Hat Enterprise Linux 8kernelUnder investigation
Red Hat Enterprise Linux 8kernel-rtUnder investigation
Red Hat Enterprise Linux 9kernelUnder investigation
Red Hat Enterprise Linux 9kernel-rtUnder investigation

Показывать по

Дополнительная информация

Дефект:
CWE-334->CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2096901kernel: insufficient TCP source port randomness leads to client identification

EPSS

Процентиль: 11%
0.00039
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 3 лет назад

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

CVSS3: 3.3
nvd
больше 3 лет назад

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

CVSS3: 3.3
msrc
больше 3 лет назад

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

CVSS3: 3.3
debian
больше 3 лет назад

The Linux kernel before 5.17.9 allows TCP servers to identify clients ...

CVSS3: 3.3
github
больше 3 лет назад

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used.

EPSS

Процентиль: 11%
0.00039
Низкий

0 Low

CVSS3