Related Vulnerabilities: CVE-2022-32296  

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used.

Description

The MITRE CVE dictionary describes this issue as:

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used.

Additional Information

  • Bugzilla 2096901: CVE-2022-32296 kernel: insufficient TCP source port randomness leads to client identification
  • CWE-330: Use of Insufficiently Random Values
  • FAQ: Frequently asked questions about CVE-2022-32296