Description
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Linux / Linux kernel4.4.276
- NETAPP / aff_a400_firmware
- NETAPP / all_flash_fabric-attached_storage_8300_firmware
- NETAPP / all_flash_fabric-attached_storage_8700_firmware
- NETAPP / brocade_fabric_operating_system_firmware
- NETAPP / e-series_santricity_os_controller
- NETAPP / fabric-attached_storage_8300_firmware
- NETAPP / fabric-attached_storage_8700_firmware
- NETAPP / fabric-attached_storage_a400_firmware
- NETAPP / h300e_firmware
- NETAPP / h300s_firmware
- NETAPP / h410c_firmware
- NETAPP / h410s_firmware
- NETAPP / h500e_firmware
- NETAPP / h500s_firmware
- NETAPP / h610c_firmware
- NETAPP / h610s_firmware
- NETAPP / h615c_firmware
- NETAPP / h700e_firmware
- NETAPP / h700s_firmware
- NETAPP / hci_compute_node_firmware
- NETAPP / solidfire,_enterprise_sds_&_hci_storage_node
- NETAPP / solidfire_&_hci_management_node
- oracle / communications_cloud_native_core_binding_support_function22.1.3 – 22.1.3
- oracle / communications_cloud_native_core_network_exposure_function22.1.1 – 22.1.1
- oracle / communications_cloud_native_core_policy22.2.0 – 22.2.0
References
- MISChttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3
- MISChttps://arxiv.org/pdf/2112.09604.pdf
- MISChttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=62f20e068ccc50d6ab66fdb72ba90da2b9418c99
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2022.html
- MISChttps://security.netapp.com/advisory/ntap-20220121-0001/
Updated 5m ago · 8 sources