kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak
Published Aug 5, 2022
8.2
HIGHCVSS 3.1
EPSS 4.12%
Description
A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Linux kernel version prior to 5.18-rc6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- < 5.18
- 5.18
- 5.18
- 5.18
- 5.18
- 5.18
- 5.18
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.19.1.el8_6
Fixed · RHSA-2022:5819
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-372.19.1.rt7.176.el8_6
Fixed · RHSA-2022:5834
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kernel-0:4.18.0-147.70.1.el8_1
Fixed · RHSA-2022:5636
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-0:4.18.0-193.87.1.el8_2
Fixed · RHSA-2022:5220
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-rt-0:4.18.0-193.87.1.rt13.137.el8_2
Fixed · RHSA-2022:5224
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.57.1.el8_4
Fixed · RHSA-2022:5626
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.57.1.rt7.129.el8_4
Fixed · RHSA-2022:5633
Red Hat Enterprise Linux 9
kernel-0:5.14.0-70.17.1.el9_0
Fixed · RHSA-2022:5249
Red Hat Enterprise Linux 9
kernel-0:5.14.0-70.17.1.el9_0
Fixed · RHSA-2022:5249
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-70.17.1.rt21.89.el9_0
Fixed · RHSA-2022:5267
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2022:5214
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.19.1.el8_6
Fixed · RHSA-2022:5819
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.2-202209140405_8.6
Fixed · RHSA-2022:6551
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.19.1.el8_6 | Fixed | RHSA-2022:5819 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-372.19.1.rt7.176.el8_6 | Fixed | RHSA-2022:5834 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel-0:4.18.0-147.70.1.el8_1 | Fixed | RHSA-2022:5636 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-0:4.18.0-193.87.1.el8_2 | Fixed | RHSA-2022:5220 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-rt-0:4.18.0-193.87.1.rt13.137.el8_2 | Fixed | RHSA-2022:5224 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.57.1.el8_4 | Fixed | RHSA-2022:5626 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.57.1.rt7.129.el8_4 | Fixed | RHSA-2022:5633 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-70.17.1.el9_0 | Fixed | RHSA-2022:5249 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-70.17.1.el9_0 | Fixed | RHSA-2022:5249 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-70.17.1.rt21.89.el9_0 | Fixed | RHSA-2022:5267 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2022:5214 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.19.1.el8_6 | Fixed | RHSA-2022:5819 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.2-202209140405_8.6 | Fixed | RHSA-2022:6551 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux version 7 (RHEL7) is not affected by this issue. While RHEL7 implements the TCP port randomization algorithm 3 (the Simple Hash-Based Port Selection Algorithm), which knowingly has shortcomings (as per RFC 6056, item 3.3.3), the object of study of this flaw was the TCP port selector algorithm 4, the Double-Hash Port Selection Algorithm, which is not existent in RHEL7. This flaw is ranked as a Moderate impact due to: * Limited exposure of the data in the TCP stack; * The impact of this vulnerability is limited to a system fingerprinting; * The requirements to carry the attack are elevated, requiring monitoring of the data flow.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.12% (0.04117) | 90.46th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.97% (0.02972) | 85.43th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.38% (0.00383) | 57.51th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.12% (0.00121) | 48.07th | v3 (v2023.03.01) |
| Mar 26, 2024 | 0.12% (0.00121) | 45.50th | v3 (v2023.03.01) |
| Mar 12, 2024 | 0.11% (0.00115) | 44.19th | v3 (v2023.03.01) |
| Jan 16, 2024 | 0.10% (0.00097) | 40.13th | v3 (v2023.03.01) |
| Sep 7, 2023 | 0.08% (0.00085) | 35.19th | v3 (v2023.03.01) |
| Aug 12, 2023 | 0.08% (0.00076) | 31.08th | v3 (v2023.03.01) |
| Jul 6, 2023 | 0.06% (0.00063) | 25.13th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00053) | 19.13th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Oct 22, 2022 | 0.95% (0.00954) | 35.07th | v2 (v2022.01.01) |
| Aug 6, 2022 | 0.89% (0.00885) | 25.91th | v2 (v2022.01.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2022-1012 Vendor Advisory
- https://arxiv.org/abs/2209.12993
- https://bugzilla.redhat.com/show_bug.cgi?id=2064604 Issue TrackingThird Party Advisory
- https://datatracker.ietf.org/doc/html/rfc6056#section-3.3.4
- https://lore.kernel.org/lkml/20220427065233.2075-1-w%401wt.eu/T/
- https://lore.kernel.org/lkml/20220428124001.7428-1-w@1wt.eu/
- https://lwn.net/Articles/910435/
- https://nvd.nist.gov/vuln/detail/CVE-2022-1012
- https://security.netapp.com/advisory/ntap-20221020-0006/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1012
Change history (0)
No recorded changes yet.