Back

HIGH

kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak

Published Aug 5, 2022

Description

A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux version 7 (RHEL7) is not affected by this issue. While RHEL7 implements the TCP port randomization algorithm 3 (the Simple Hash-Based Port Selection Algorithm), which knowingly has shortcomings (as per RFC 6056, item 3.3.3), the object of study of this flaw was the TCP port selector algorithm 4, the Double-Hash Port Selection Algorithm, which is not existent in RHEL7. This flaw is ranked as a Moderate impact due to: * Limited exposure of the data in the TCP stack; * The impact of this vulnerability is limited to a system fingerprinting; * The requirements to carry the attack are elevated, requiring monitoring of the data flow.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 5, 2022
Updated Aug 2, 2024
Reserved Mar 17, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 2, 2022