CVE-2019-18282

CVSS v3.1 5.3 (Medium)
53% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.25 % (65th)
0.25% Progress
Affected Products 19
Advisories 7

The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.

Weaknesses
CWE-330
Use of Insufficiently Random Values
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2020-01-16 16:15:16
(4 years ago)
Updated Date
2022-04-18 15:48:24
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Linux Kernel from 4.3 version and 5.3.10 and prior versions cpe:2.3:o:linux:linux_kernel >= 4.3 <= 5.3.10

Configuration #2

AND
    CPE23 From Up To
OR  
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #3

AND
    CPE23 From Up To
OR  
  Netapp A700s Firmware cpe:2.3:o:netapp:a700s_firmware:-
OR  
  Running on/with
  Netapp A700s cpe:2.3:h:netapp:a700s:-

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp 8300 Firmware cpe:2.3:o:netapp:8300_firmware:-
OR  
  Running on/with
  Netapp 8300 cpe:2.3:h:netapp:8300:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp 8700 Firmware cpe:2.3:o:netapp:8700_firmware:-
OR  
  Running on/with
  Netapp 8700 cpe:2.3:h:netapp:8700:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp A400 Firmware cpe:2.3:o:netapp:a400_firmware:-
OR  
  Running on/with
  Netapp A400 cpe:2.3:h:netapp:a400:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H610s Firmware cpe:2.3:o:netapp:h610s_firmware:-
OR  
  Running on/with
  Netapp H610s cpe:2.3:h:netapp:h610s:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp Active Iq Unified Manager for Vmware Vsphere cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere
OR  
  Running on/with
  Netapp Cloud Backup cpe:2.3:a:netapp:cloud_backup:-
OR  
  Running on/with
  Netapp Data Availability Services cpe:2.3:a:netapp:data_availability_services:-
OR  
  Running on/with
  Netapp E-series Santricity Os Controller from 11.0.0 version and 11.70.1 and prior versions cpe:2.3:a:netapp:e-series_santricity_os_controller >= 11.0.0 <= 11.70.1
OR  
  Running on/with
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
OR  
  Running on/with
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-
OR  
  Running on/with
  Netapp Steelstore Cloud Integrated Storage cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...