CVE-2019-18282
published 2020-01-16CVE-2019-18282: The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.60%
83.6th percentile
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.3.15-1 (bookworm) | linux 5.3.15-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 5.3.15-1 | 5.3.15-1 |
| linux | linux_kernel | >= 0 < 5.3.15-1 | 5.3.15-1 |
| linux | linux_kernel | >= 0 < 5.3.15-1 | 5.3.15-1 |
| linux | linux_kernel | >= 0 < 5.3.15-1 | 5.3.15-1 |
| linux | linux_kernel | 4.3 – 5.3.10 | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.70.1 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gc9j-xjc6-h7v6: The flow_dissector feature in the Linux kernel 4
ghsa_unreviewed·2022-05-24
CVE-2019-18282 [MEDIUM] CWE-200 GHSA-gc9j-xjc6-h7v6: The flow_dissector feature in the Linux kernel 4
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashmd value as a secret, and because jhash (instead of siphash) is used. The hashmd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
OSV
CVE-2019-18282: In __flow_hash_from_keys of flow_dissector
osv·2020-07-01
CVE-2019-18282 CVE-2019-18282: In __flow_hash_from_keys of flow_dissector
In __flow_hash_from_keys of flow_dissector.c, there is a possible packet injection due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2019-18282: The flow_dissector feature in the Linux kernel 4
osv·2020-01-16·CVSS 5.3
CVE-2019-18282 [MEDIUM] CVE-2019-18282: The flow_dissector feature in the Linux kernel 4
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
Android
CVE-2019-18282: Linux Networking Stack
vendor_android·2020-07-01·CVSS 5.3
CVE-2019-18282 [MEDIUM] CVE-2019-18282: Linux Networking Stack
Android Security Bulletin 2020-07-01
CVE: CVE-2019-18282
Severity: HIGH
Type: EoP
Component: Linux Networking Stack
References: A-148588557
Upstream kernel
Red Hat
kernel: The flow_dissector feature allows device tracking
vendor_redhat·2019-10-22·CVSS 5.3
CVE-2019-18282 [MEDIUM] CWE-200 kernel: The flow_dissector feature allows device tracking
kernel: The flow_dissector feature allows device tracking
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
A device tracking vulnerability was found in the flow_dissector feature in the Linux kernel. This flaw occurs because the auto flowlabel of the UDP IPv6 packet relies on a 32-bit hashmd value as a secret, and jhash (instead of siphash) is used. The hashmd value remains the same starting from boot
Debian
CVE-2019-18282: linux - The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has...
vendor_debian·2019·CVSS 5.3
CVE-2019-18282 [MEDIUM] CVE-2019-18282: linux - The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has...
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
Scope: local
bookworm: resolved (fixed in 5.3.15-1)
bullseye: resolved (fixed in 5.3.15-1)
forky: resolved (fixed in 5.3.15-1)
sid: resolved (fixed in 5.3.15-1)
trixie: resolved (fixed in 5.3.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18282 kernel: The flow_dissector feature allows device tracking
bugzilla·2020-01-30·CVSS 5.3
CVE-2019-18282 [MEDIUM] CVE-2019-18282 kernel: The flow_dissector feature allows device tracking
CVE-2019-18282 kernel: The flow_dissector feature allows device tracking
The flow_dissector feature in the Linux kernel has a device tracking vulnerability. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashmd value as a secret, and because jhash (instead of siphash) is used. The hashmd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.
Upstream commit:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=55667441c84fa5e0911a0aac44fb059c15ba6da2
References:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.10
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1796364]
---
This was fixed for Fedora
Bugzilla
CVE-2019-18282 kernel: The flow_dissector feature allows device tracking [fedora-all]
bugzilla·2020-01-30·CVSS 5.3
CVE-2019-18282 [MEDIUM] CVE-2019-18282 kernel: The flow_dissector feature allows device tracking [fedora-all]
CVE-2019-18282 kernel: The flow_dissector feature allows device tracking [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2019-18282 kernel: flow_dissector allows device tracking [fedora-all]
bugzilla·2020-01-30·CVSS 5.3
CVE-2019-18282 [MEDIUM] CVE-2019-18282 kernel: flow_dissector allows device tracking [fedora-all]
CVE-2019-18282 kernel: flow_dissector allows device tracking [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.10https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=55667441c84fa5e0911a0aac44fb059c15ba6da2https://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20200204-0002/https://www.computer.org/csdl/proceedings-article/sp/2020/349700b594/1j2LgrHDR2ohttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.10https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=55667441c84fa5e0911a0aac44fb059c15ba6da2https://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20200204-0002/https://www.computer.org/csdl/proceedings-article/sp/2020/349700b594/1j2LgrHDR2o
2020-01-16
Published