The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernelUpgrade kernel-rt | Jun 1, 2020 | Jan 16, 2020 |
| Debian | — | Upgrade linux | Feb 24, 2020 | Jan 16, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 8, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade kernel-tools-libsUpgrade python-perfUpgrade kernel-sourceUpgrade kernel-toolsUpgrade kernelUpgrade kernel-headersUpgrade bpftoolUpgrade perfUpgrade python3-perfUpgrade kernel-devel | Jul 31, 2020 | Jan 16, 2020 |
| Oracle_linux | — | Upgrade kernel-uekUpgrade kernel | Dec 17, 2020 | Oct 22, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Jan 16, 2020 |
| Redhat_linux | — | Upgrade kernel-rtNo solution existsUpgrade kernel | Jun 1, 2020 | Jan 16, 2020 |
| Ubuntu | — | Upgrade linux-hwe-edgeUpgrade linux-lts-xenialUpgrade linux-awsUpgrade linux-fipsUpgrade linux-gcp-5.3Upgrade linux-snapdragonUpgrade linux-oracle-5.0Upgrade linux-aws-hweUpgrade linux-oemUpgrade linux-gke-4.15Upgrade linux-azure-5.3Upgrade linux-oem-osp1Upgrade linux-azureUpgrade linux-aws-5.0Upgrade linux-azure-fipsUpgrade linux-hweUpgrade linux-aws-fipsUpgrade linux-gcpUpgrade linux-raspi2Upgrade linuxUpgrade linux-kvmUpgrade linux-gke-5.0Upgrade linux-oracle | Nov 19, 2024 | Jan 16, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub