PT-2022-3221 · Linux+5 · Linux Kernel+5
Amit Klein
+2
·
Published
2022-05-18
·
Updated
2023-08-14
·
CVE-2022-32296
CVSS v2.0
4.9
Medium
| Vector | AV:N/AC:H/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.17.9
Description
The issue is related to insufficient entropy in the Linux kernel, allowing a remote attacker to identify clients by determining the original source ports used by the TCP server. This is due to the use of Algorithm 4, also known as the Double-Hash Port Selection Algorithm, as defined in RFC 6056.
Recommendations
For Linux kernel versions prior to 5.17.9, update to version 5.17.9 or later to resolve the issue.
Fix
Side Channel Attack
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu