Skip to content

kernel CVE-2022-32296

Moderate
rpkelly published GHSA-cghh-fpjf-mmww Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.4 (bottlerocket)
< 1.9.0
1.9.0

Description

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used.

Severity

Moderate

CVE ID

CVE-2022-32296

Weaknesses

No CWEs