CVE-2021-45485
kernel: information leak in the IPv6 implementation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
En la implementación de IPv6 en el kernel de Linux versiones anteriores a 5.13.3, el archivo net/ipv6/output_core.c presenta un filtrado de información debido a determinado uso de una tabla hash que, aunque es grande, no considera apropiadamente que atacantes basados en IPv6 pueden elegir típicamente entre muchas direcciones de origen IPv6
An information leak flaw was found in the Linux kernel’s IPv6 implementation in the __ipv6_select_ident in net/ipv6/output_core.c function. The use of a small hash table in IP ID generation allows a remote attacker to reveal sensitive information.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-25 CVE Reserved
- 2021-12-25 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://arxiv.org/pdf/2112.09604.pdf | Technical Description | |
https://security.netapp.com/advisory/ntap-20220121-0001 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3 | 2023-02-24 | |
https://access.redhat.com/security/cve/CVE-2021-45485 | 2022-10-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2039911 | 2022-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netapp Search vendor "Netapp" | All Flash Fabric-attached Storage 8300 Firmware Search vendor "Netapp" for product "All Flash Fabric-attached Storage 8300 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | All Flash Fabric-attached Storage 8300 Search vendor "Netapp" for product "All Flash Fabric-attached Storage 8300" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Fabric-attached Storage 8300 Firmware Search vendor "Netapp" for product "Fabric-attached Storage 8300 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Fabric-attached Storage 8300 Search vendor "Netapp" for product "Fabric-attached Storage 8300" | - | - |
Safe
|
Netapp Search vendor "Netapp" | All Flash Fabric-attached Storage 8700 Firmware Search vendor "Netapp" for product "All Flash Fabric-attached Storage 8700 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | All Flash Fabric-attached Storage 8700 Search vendor "Netapp" for product "All Flash Fabric-attached Storage 8700" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Fabric-attached Storage 8700 Firmware Search vendor "Netapp" for product "Fabric-attached Storage 8700 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Fabric-attached Storage 8700 Search vendor "Netapp" for product "Fabric-attached Storage 8700" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Aff A400 Firmware Search vendor "Netapp" for product "Aff A400 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Aff A400 Search vendor "Netapp" for product "Aff A400" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Fabric-attached Storage A400 Firmware Search vendor "Netapp" for product "Fabric-attached Storage A400 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Fabric-attached Storage A400 Search vendor "Netapp" for product "Fabric-attached Storage A400" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Hci Compute Node Firmware Search vendor "Netapp" for product "Hci Compute Node Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Hci Compute Node Search vendor "Netapp" for product "Hci Compute Node" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H300e Firmware Search vendor "Netapp" for product "H300e Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H300e Search vendor "Netapp" for product "H300e" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H300s Firmware Search vendor "Netapp" for product "H300s Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H300s Search vendor "Netapp" for product "H300s" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H410c Firmware Search vendor "Netapp" for product "H410c Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H410c Search vendor "Netapp" for product "H410c" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H410s Firmware Search vendor "Netapp" for product "H410s Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H410s Search vendor "Netapp" for product "H410s" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H500e Firmware Search vendor "Netapp" for product "H500e Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H500e Search vendor "Netapp" for product "H500e" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H500s Firmware Search vendor "Netapp" for product "H500s Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H500s Search vendor "Netapp" for product "H500s" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H610c Firmware Search vendor "Netapp" for product "H610c Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H610c Search vendor "Netapp" for product "H610c" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H610s Firmware Search vendor "Netapp" for product "H610s Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H610s Search vendor "Netapp" for product "H610s" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H615c Firmware Search vendor "Netapp" for product "H615c Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H615c Search vendor "Netapp" for product "H615c" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H700e Firmware Search vendor "Netapp" for product "H700e Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H700e Search vendor "Netapp" for product "H700e" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H700s Firmware Search vendor "Netapp" for product "H700s Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H700s Search vendor "Netapp" for product "H700s" | - | - |
Safe
|
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | < 5.13.3 Search vendor "Linux" for product "Linux Kernel" and version " < 5.13.3" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Os Controller Search vendor "Netapp" for product "E-series Santricity Os Controller" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire\, Enterprise Sds \& Hci Storage Node Search vendor "Netapp" for product "Solidfire\, Enterprise Sds \& Hci Storage Node" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire \& Hci Management Node Search vendor "Netapp" for product "Solidfire \& Hci Management Node" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Brocade Fabric Operating System Firmware Search vendor "Netapp" for product "Brocade Fabric Operating System Firmware" | - | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Binding Support Function Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" | 22.1.3 Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" and version "22.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Network Exposure Function Search vendor "Oracle" for product "Communications Cloud Native Core Network Exposure Function" | 22.1.1 Search vendor "Oracle" for product "Communications Cloud Native Core Network Exposure Function" and version "22.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Policy Search vendor "Oracle" for product "Communications Cloud Native Core Policy" | 22.2.0 Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "22.2.0" | - |
Affected
|