CVE-2021-45485
published 2021-12-25CVE-2021-45485: In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.58%
88.2th percentile
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux_kernel | < 5.13.3 | 5.13.3 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-222.255 | 4.4.0-222.255 |
| linux | linux_kernel | >= 0 < 4.4.0-219.252 | 4.4.0-219.252 |
| msrc | cbl2_kernel_5.15.2.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_kernel_5.10.88.1-2_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 7.8
CVE-2020-25673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly us
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-02-22·CVSS 5.4
CVE-2020-26558 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation could
reassemble mixed encrypted and plaintext fragments. A physically proximate
attacker could possibly use this issue to inject packets or exfiltrate
selected fragments. (CVE-2020-26147)
It was discovered that the bluetooth subsystem in the Linux kernel did not
properly perform access control. An authenticated attacker could possibly
use this to expose sensitive information. (CVE-2020-26558, CVE-2021-0129)
It was discovered that the RPA PCI Hotplug driver implementation in the
Linux kernel did not properly handle device name writes via sysfs, leading
to a buffer overflow. A privileged attacker could use this to cause
Microsoft
In the IPv6 implementation in the Linux kernel before 5.13.3 net/ipv6/output_core.c has an information leak because of certain use of a hash table which although big doesn't properly consider that IPv
vendor_msrc·2021-12-14·CVSS 7.5
CVE-2021-45485 [HIGH] CWE-327 In the IPv6 implementation in the Linux kernel before 5.13.3 net/ipv6/output_core.c has an information leak because of certain use of a hash table which although big doesn't properly consider that IPv
In the IPv6 implementation in the Linux kernel before 5.13.3 net/ipv6/output_core.c has an information leak because of certain use of a hash table which although big doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more informa
Red Hat
kernel: information leak in the IPv6 implementation
vendor_redhat·2021-05-31·CVSS 7.5
CVE-2021-45485 [HIGH] CWE-327 kernel: information leak in the IPv6 implementation
kernel: information leak in the IPv6 implementation
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
An information leak flaw was found in the Linux kernel’s IPv6 implementation in the __ipv6_select_ident in net/ipv6/output_core.c function. The use of a small hash table in IP ID generation allows a remote attacker to reveal sensitive information.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installa
Debian
CVE-2021-45485: linux - In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_co...
vendor_debian·2021·CVSS 7.5
CVE-2021-45485 [HIGH] CVE-2021-45485: linux - In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_co...
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-03-22·CVSS 7.8
CVE-2022-0492 [HIGH] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly use this to gain
elevated privileges. (CVE
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-02-22·CVSS 5.4
CVE-2020-26147 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation could
reassemble mixed encrypted and plaintext fragments. A physically proximate
attacker could possibly use this issue to inject packets or exfiltrate
selected fragments. (CVE-2020-26147)
It was discovered that the bluetooth subsystem in the Linux kernel did not
properly perform access control. An authenticated attacker could possibly
use this to expose sensitive information. (CVE-2020-26558, CVE-2021-0129)
It was discovered that the RPA PCI Hotplug driver implementation in the
Linux kernel did not properly handle device name writes via sysfs, leading
to a buffer overflow. A privileged attacker could use this to cause a
denial of service (system crash) or p
GHSA
GHSA-4q84-7284-2fp5: In the IPv6 implementation in the Linux kernel before 5
ghsa_unreviewed·2021-12-26
CVE-2021-45485 [HIGH] CWE-327 GHSA-4q84-7284-2fp5: In the IPv6 implementation in the Linux kernel before 5
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
OSV
CVE-2021-45485: In the IPv6 implementation in the Linux kernel before 5
osv·2021-12-25·CVSS 7.5
CVE-2021-45485 [HIGH] CVE-2021-45485: In the IPv6 implementation in the Linux kernel before 5
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
No detection rules found.
No public exploits indexed.
arXiv
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
arxiv_fulltext·2026-01-28
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
195
195
41
4.76
2
1
100
1
3
100
51.3%
51%
8
4.1%
4%
5
2.6%
3%
5
2.6%
3%
5
2.6%
3%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
135
60
195
0.69
69
0.48
0.59
52
35
87
0.6
60
0.6
9
8
4
13
0.69
69
[Detecting One-day Vulnerabilities in Open-source Forks With Global History Analysis]Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source Forks With Global History Analysis
[Lefeuvre]Romain Lefeuvre
University of Rennes
Rennes
France
[email protected]
[Reux]Char
arXiv
Subverting Stateful Firewalls with Protocol States (Extended Version)
arxiv_fulltext·2022-08-31
Subverting Stateful Firewalls with Protocol States (Extended Version)
Subverting Stateful Firewalls with Protocol States
(Extended Version) (This is an extended version of a paper that will be published in NDSS 2022.)
Amit Klein
0000-0002-8024-8756
Bar Ilan University
[email protected]
## Abstract
We analyzed the generation of protocol header fields in the implementations of multiple TCP/IP network stacks and found new ways to leak information about global protocol states. We then demonstrated new covert channels by remotely observing and modifying the system's global state via these protocol fields. Unlike earlier works, our research focuses on hosts that reside in firewalled networks (including source address validation -- SAV), which is a very common scenario nowadays. Our attacks are designed to be non-disruptive -- in the exfiltration scenario,
https://arxiv.org/pdf/2112.09604.pdfhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=62f20e068ccc50d6ab66fdb72ba90da2b9418c99https://security.netapp.com/advisory/ntap-20220121-0001/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://arxiv.org/pdf/2112.09604.pdfhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=62f20e068ccc50d6ab66fdb72ba90da2b9418c99https://security.netapp.com/advisory/ntap-20220121-0001/https://www.oracle.com/security-alerts/cpujul2022.html
2021-12-25
Published