Use of Weak Hash Affecting gvisor.dev/gvisor/pkg/tcpip/network/ipv6 package, versions <20231204.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use of Weak Hash vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GVISORDEVGVISORPKGTCPIPNETWORKIPV6-8679648
  • published31 Jan 2025
  • disclosed31 Jan 2025
  • creditInon Kaplan, Ron Even, Amit Klein

Introduced: 31 Jan 2025

NewCVE-2024-10026  (opens in a new tab)
CWE-328  (opens in a new tab)
CWE-339  (opens in a new tab)

How to fix?

Upgrade gvisor.dev/gvisor/pkg/tcpip/network/ipv6 to version 20231204.0.0 or higher.

Overview

Affected versions of this package are vulnerable to Use of Weak Hash and small seed sizes. An attacker can calculate a local IP address and a per-boot identifier, which could be used to track a device under certain conditions.

CVSS Scores

version 4.0
version 3.1