The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernel-rtUpgrade kernel | Jun 1, 2020 | Jan 16, 2020 |
| Debian | — | Upgrade linux | Feb 24, 2020 | Jan 16, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 8, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade kernel-tools-libsUpgrade python-perfUpgrade kernel-sourceUpgrade kernel-toolsUpgrade kernelUpgrade python3-perfUpgrade bpftoolUpgrade kernel-headersUpgrade perfUpgrade kernel-devel | Jul 31, 2020 | Jan 16, 2020 |
| Oracle_linux | — | Upgrade kernelUpgrade kernel-uek | Dec 17, 2020 | Oct 22, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Jan 16, 2020 |
| Redhat_linux | — | Upgrade kernelUpgrade kernel-rtNo solution exists | Jun 1, 2020 | Jan 16, 2020 |
| Ubuntu | — | Upgrade linux-oracle-5.0Upgrade linux-oem-osp1Upgrade linux-hwe-edgeUpgrade linux-gke-4.15Upgrade linux-gcp-5.3Upgrade linux-azureUpgrade linux-fipsUpgrade linux-aws-hweUpgrade linux-awsUpgrade linux-azure-5.3Upgrade linux-lts-xenialUpgrade linux-snapdragonUpgrade linux-oemUpgrade linux-gke-5.0Upgrade linux-raspi2Upgrade linux-kvmUpgrade linux-aws-fipsUpgrade linux-hweUpgrade linux-aws-5.0Upgrade linux-gcpUpgrade linux-azure-fipsUpgrade linuxUpgrade linux-oracle | Nov 19, 2024 | Jan 16, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub