Information Exposure Affecting torvalds/linux package, versions [,3.14.5)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.01% (76th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TORVALDSLINUX-3005045
  • published26 Jan 2022
  • disclosed13 Oct 2014
  • creditUnknown

Introduced: 13 Oct 2014

CVE-2014-7284  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade torvalds/linux to version 3.14.5 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure. The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values.

References

CVSS Base Scores

version 3.1