The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernelUpgrade kernel-rt | Jun 1, 2020 | Jan 16, 2020 |
| Debian | — | Upgrade linux | Feb 24, 2020 | Jan 16, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 8, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade kernel-sourceUpgrade kernel-toolsUpgrade kernel-tools-libsUpgrade python-perfUpgrade kernel-headersUpgrade python3-perfUpgrade perfUpgrade kernel-develUpgrade kernelUpgrade bpftool | Jul 31, 2020 | Jan 16, 2020 |
| Oracle_linux | — | Upgrade kernelUpgrade kernel-uek | Dec 17, 2020 | Oct 22, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Jan 16, 2020 |
| Redhat_linux | — | No solution existsUpgrade kernel-rtUpgrade kernel | Jun 1, 2020 | Jan 16, 2020 |
| Ubuntu | — | Upgrade linux-azure-5.3Upgrade linux-oemUpgrade linux-gcp-5.3Upgrade linux-oem-osp1Upgrade linux-azureUpgrade linux-lts-xenialUpgrade linux-oracle-5.0Upgrade linux-awsUpgrade linux-aws-hweUpgrade linux-gke-4.15Upgrade linux-hwe-edgeUpgrade linux-fipsUpgrade linux-snapdragonUpgrade linuxUpgrade linux-azure-fipsUpgrade linux-hweUpgrade linux-aws-5.0Upgrade linux-gcpUpgrade linux-raspi2Upgrade linux-oracleUpgrade linux-kvmUpgrade linux-gke-5.0Upgrade linux-aws-fips | Nov 19, 2024 | Jan 16, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub