CVE-2021-45485: High severity Linux Linux kernel vulnerability
An information leak flaw was found in the Linux kernel’s IPv6 implementation in the ipv6selectident in net/ipv6/outputcore.c function. The use of a small hash table in IP ID generation allows a remote attacker to reveal sensitive information.
Other sources
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/outputcore.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-372.9.1.rt7.166.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-372.9.1.el8 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.65.1.rt7.137.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.65.1.el8_4 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.14
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-45485?
CVE-2021-45485 is classified as a medium severity information leak vulnerability in the Linux kernel.
How do I fix CVE-2021-45485?
To fix CVE-2021-45485, update to the latest kernel versions specified in the advisory, such as kernel version 5.14 or specific Red Hat versions.
Which versions of the Linux kernel are affected by CVE-2021-45485?
Affected versions include the Linux kernel prior to 5.14 and specific earlier Red Hat kernel packages.
What type of information can be leaked by CVE-2021-45485?
CVE-2021-45485 allows remote attackers to potentially reveal sensitive information from the system due to flawed IPv6 implementation.
Is CVE-2021-45485 easy to exploit?
CVE-2021-45485 requires a remote attacker to send crafted IPv6 packets, making it a moderate risk for exposure.