In the IPv6 implementation in the Linux kernel before 5...
High severity
Unreviewed
Published
Dec 26, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Dec 25, 2021
Published to the GitHub Advisory Database
Dec 26, 2021
Last updated
Jan 27, 2023
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
References