-

CVE-2026-23247

tcp: secure_seq: add back ports to TS offset

In the Linux kernel, the following vulnerability has been resolved:

tcp: secure_seq: add back ports to TS offset

This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets")

tcp_tw_recycle went away in 2017.

Zhouyan Deng reported off-path TCP source port leakage via
SYN cookie side-channel that can be fixed in multiple ways.

One of them is to bring back TCP ports in TS offset randomization.

As a bonus, we perform a single siphash() computation
to provide both an ISN and a TS offset.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 28ee1b746f493b7c62347d714f58fbf4f70df4f0
Version < eae2f14ab2efccdb7480fae7d42c4b0116ef8805
Status affected
Version 28ee1b746f493b7c62347d714f58fbf4f70df4f0
Version < 46e5b0d7cf55821527adea471ffe52a5afbd9caf
Status affected
Version 28ee1b746f493b7c62347d714f58fbf4f70df4f0
Version < 165573e41f2f66ef98940cf65f838b2cb575d9d1
Status affected
Version 443fac9f2618b93cbc5ab068dc594530236b3a23
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.11
Status affected
Version 0
Version < 4.11
Status unaffected
Version <= 6.18.*
Version 6.18.17
Status unaffected
Version <= 6.19.*
Version 6.19.7
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.066
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.