PT-2022-3221 · Linux+5 · Linux Kernel+5

Amit Klein

+2

·

Published

2022-05-18

·

Updated

2023-08-14

·

CVE-2022-32296

CVSS v2.0

4.9

Medium

VectorAV:N/AC:H/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.9
Description The issue is related to insufficient entropy in the Linux kernel, allowing a remote attacker to identify clients by determining the original source ports used by the TCP server. This is due to the use of Algorithm 4, also known as the Double-Hash Port Selection Algorithm, as defined in RFC 6056.
Recommendations For Linux kernel versions prior to 5.17.9, update to version 5.17.9 or later to resolve the issue.

Fix

Side Channel Attack

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1886
ALT-PU-2022-1971
ALT-PU-2022-2152
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-9910
BDU:2022-03921
CVE-2022-32296
DLA-3065-1
DSA-5173-1
OESA-2022-1725
OPENSUSE-SU-2022_3693-1
OPENSUSE-SU-2022_3844-1
OPENSUSE-SU-2022_4617-1
SUSE-SU-2022:3693-1
SUSE-SU-2022:3704-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:3844-1
SUSE-SU-2022:4617-1
USN-5616-1
USN-5622-1
USN-5623-1
USN-5630-1
USN-5639-1
USN-5647-1
USN-5654-1
USN-5660-1
USN-5669-1
USN-5669-2
USN-5678-1
USN-5679-1
USN-5684-1
USN-5687-1
USN-5695-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu