Back

MEDIUM

kernel: randomness degradation due to bug in net_get_random_once()

Published Oct 13, 2014

Description

The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 13, 2014
Updated Aug 6, 2024
Reserved Oct 1, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 1, 2014