cbcvebase.
CVE-2022-32296
published 2022-06-05

CVE-2022-32296: The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4…

PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.43%
35.5th percentile
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.11-1 (bookworm)linux 5.17.11-1 (bookworm)
linuxlinux_kernel< 5.17.95.17.9
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 4.15.0-194.2054.15.0-194.205
linuxlinux_kernel>= 0 < 5.4.0-126.1425.4.0-126.142
msrccbl2_kernel_5.15.48.1-2_on_cbl_mariner_2.0
msrccm1_kernel_5.10.131.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.7MEDIUM
vendor_redhat8.2HIGH
vendor_ubuntu6.7MEDIUM
vendor_debian3.3LOW
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.