Information disclosure in Linux kernel - CVE-2019-18282
Published: March 9, 2021
Vulnerability details
The vulnerability allows a remote attacker to track devices via UDP packets.
The vulnerability exists due to excessive data output in the flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 and affects net/core/flow_dissector.c and
related code. The auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd
value as a secret, and because jhash (instead of siphash) is used. The
hashrnd value remains the same starting from boot time, and can be
inferred by an attacker. A remote attacker can use the
hashrnd value and track reliably track activity of devices using UDP packets.
Affected software
F5OS
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
BIG-IQ Centralized Management
BIG-IP GTM
BIG-IP LTM
BIG-IP FPS
BIG-IP AFM
BIG-IP ASM
BIG-IP Analytics
BIG-IP PEM
BIG-IP APM
BIG-IP AAM
BIG-IP Link Controller
BIG-IP DNS
BIG-IP Advanced WAF
BIG-IP
BIG-IP DDHD
BIG-IP SSLO
kernel (Red Hat package)
kernel-rt (Red Hat package)
Data Computing Appliance (DCA)
IBM QRadar Network Security
Session Smart Router
How to mitigate CVE-2019-18282
kernel (Red Hat package) - update to 3.10.0-1160.11.1.el7
kernel-rt (Red Hat package) - update to 3.10.0-1160.11.1.rt56.1145.el7
Data Computing Appliance (DCA) - update to 4.3.0.0
IBM QRadar Network Security - addressed in versions 5.4.0.17, 5.5.0.12
Session Smart Router - addressed in versions 5.4.7, 5.5.3
External References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.10
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=55667441c84fa5e0911a0aac44fb059c15ba6da2
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://security.netapp.com/advisory/ntap-20200204-0002/
- https://www.computer.org/csdl/proceedings-article/sp/2020/349700b594/1j2LgrHDR2o
Related Security Bulletins
- Device tracking vulnerability via UDP in Linux kernel
- System tracking vulnerability in Linux kernel in F5 BIP-IP products
- System tracking vulnerability in Linux kernel in F5OS
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in IBM QRadar Network Security
- Red Hat Enterprise Linux 7 update for kernel
- Red Hat Enterprise Linux 7 update for kernel-rt