CVE-2026-23247
published 2026-03-18CVE-2026-23247: In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_seq…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
tcp: secure_seq: add back ports to TS offset
This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets")
tcp_tw_recycle went away in 2017.
Zhouyan Deng reported off-path TCP source port leakage via
SYN cookie side-channel that can be fixed in multiple ways.
One of them is to bring back TCP ports in TS offset randomization.
As a bonus, we perform a single siphash() computation
to provide both an ISN and a TS offset.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 28ee1b746f493b7c62347d714f58fbf4f70df4f0 < 5da5662181ef8a251e3ba564903002c2e87de452 | 5da5662181ef8a251e3ba564903002c2e87de452 |
| linux | linux | >= 28ee1b746f493b7c62347d714f58fbf4f70df4f0 < eae2f14ab2efccdb7480fae7d42c4b0116ef8805 | eae2f14ab2efccdb7480fae7d42c4b0116ef8805 |
| linux | linux | >= 28ee1b746f493b7c62347d714f58fbf4f70df4f0 < 46e5b0d7cf55821527adea471ffe52a5afbd9caf | 46e5b0d7cf55821527adea471ffe52a5afbd9caf |
| linux | linux | >= 28ee1b746f493b7c62347d714f58fbf4f70df4f0 < 165573e41f2f66ef98940cf65f838b2cb575d9d1 | 165573e41f2f66ef98940cf65f838b2cb575d9d1 |
| linux | linux | >= 4.10.14 < 4.11 | 4.11 |
| linux | linux_kernel | < 6.18.17 | 6.18.17 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 4.11.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
| msrc | azl3_kernel_6.6.126.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 tcp siphash downgrade (EUVD-2026-12810 / Nessus ID 302908)
vuldb·2026-06-24·CVSS 5.5
CVE-2026-23247 [MEDIUM] Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 tcp siphash downgrade (EUVD-2026-12810 / Nessus ID 302908)
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.18.16/6.19.6/7.0-rc2. Impacted is the function siphash of the component tcp. The manipulation leads to algorithm downgrade.
This vulnerability is documented as CVE-2026-23247. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
OSV
tcp: secure_seq: add back ports to TS offset
osv·2026-03-18
CVE-2026-23247 tcp: secure_seq: add back ports to TS offset
tcp: secure_seq: add back ports to TS offset
In the Linux kernel, the following vulnerability has been resolved:
tcp: secure_seq: add back ports to TS offset
This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets")
tcp_tw_recycle went away in 2017.
Zhouyan Deng reported off-path TCP source port leakage via
SYN cookie side-channel that can be fixed in multiple ways.
One of them is to bring back TCP ports in TS offset randomization.
As a bonus, we perform a single siphash() computation
to provide both an ISN and a TS offset.
GHSA
GHSA-4hcm-qg7j-cc3v: In the Linux kernel, the following vulnerability has been resolved:
tcp: secure_seq: add back ports to TS offset
This reverts 28ee1b746f49 ("secure_
ghsa_unreviewed·2026-03-18
CVE-2026-23247 GHSA-4hcm-qg7j-cc3v: In the Linux kernel, the following vulnerability has been resolved:
tcp: secure_seq: add back ports to TS offset
This reverts 28ee1b746f49 ("secure_
In the Linux kernel, the following vulnerability has been resolved:
tcp: secure_seq: add back ports to TS offset
This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets")
tcp_tw_recycle went away in 2017.
Zhouyan Deng reported off-path TCP source port leakage via
SYN cookie side-channel that can be fixed in multiple ways.
One of them is to bring back TCP ports in TS offset randomization.
As a bonus, we perform a single siphash() computation
to provide both an ISN and a TS offset.
OSV
CVE-2026-23247: In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_se
osv·2026-03-18
CVE-2026-23247 CVE-2026-23247: In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_se
In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets") tcp_tw_recycle went away in 2017. Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways. One of them is to bring back TCP ports in TS offset randomization. As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset.
Red Hat
kernel: tcp: secure_seq: add back ports to TS offset
vendor_redhat·2026-03-18·CVSS 5.5
CVE-2026-23247 [LOW] kernel: tcp: secure_seq: add back ports to TS offset
kernel: tcp: secure_seq: add back ports to TS offset
In the Linux kernel, the following vulnerability has been resolved:
tcp: secure_seq: add back ports to TS offset
This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets")
tcp_tw_recycle went away in 2017.
Zhouyan Deng reported off-path TCP source port leakage via
SYN cookie side-channel that can be fixed in multiple ways.
One of them is to bring back TCP ports in TS offset randomization.
As a bonus, we perform a single siphash() computation
to provide both an ISN and a TS offset.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux
Microsoft
tcp: secure_seq: add back ports to TS offset
vendor_msrc·2026-03-10·CVSS 6.5
CVE-2026-23247 [MEDIUM] tcp: secure_seq: add back ports to TS offset
tcp: secure_seq: add back ports to TS offset
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2026-23247: linux - In the Linux kernel, the following vulnerability has been resolved: tcp: secure...
vendor_debian·2026
CVE-2026-23247 CVE-2026-23247: linux - In the Linux kernel, the following vulnerability has been resolved: tcp: secure...
In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets") tcp_tw_recycle went away in 2017. Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways. One of them is to bring back TCP ports in TS offset randomization. As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: open
No detection rules found.
No public exploits indexed.
2026-03-18
Published