Related Vulnerabilities: CVE-2020-36516  

An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.

Description

The MITRE CVE dictionary describes this issue as:

An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.

Additional Information

  • Bugzilla 2059928: CVE-2020-36516 kernel: an off-path attacker may inject data or terminate a victim's TCP session
  • CWE-287: Improper Authentication
  • FAQ: Frequently asked questions about CVE-2020-36516