The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernelUpgrade kernel-rt | Jun 1, 2020 | Jan 16, 2020 |
| Debian | — | Upgrade linux | Feb 24, 2020 | Jan 16, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 8, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python-perfUpgrade kernel-tools-libsUpgrade kernel-sourceUpgrade kernel-toolsUpgrade kernel-develUpgrade bpftoolUpgrade kernelUpgrade python3-perfUpgrade perfUpgrade kernel-headers | Jul 31, 2020 | Jan 16, 2020 |
| Oracle_linux | — | Upgrade kernel-uekUpgrade kernel | Dec 17, 2020 | Oct 22, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Jan 16, 2020 |
| Redhat_linux | — | No solution existsUpgrade kernel-rtUpgrade kernel | Jun 1, 2020 | Jan 16, 2020 |
| Ubuntu | — | Upgrade linux-aws-5.0Upgrade linux-kvmUpgrade linux-hweUpgrade linux-azure-fipsUpgrade linuxUpgrade linux-aws-fipsUpgrade linux-gke-5.0Upgrade linux-raspi2Upgrade linux-oracleUpgrade linux-gcpUpgrade linux-fipsUpgrade linux-awsUpgrade linux-aws-hweUpgrade linux-hwe-edgeUpgrade linux-lts-xenialUpgrade linux-azure-5.3Upgrade linux-oem-osp1Upgrade linux-oracle-5.0Upgrade linux-gcp-5.3Upgrade linux-azureUpgrade linux-oemUpgrade linux-snapdragonUpgrade linux-gke-4.15 | Nov 19, 2024 | Jan 16, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub