CVE-2024-10026

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Feb 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Un algoritmo hash débil y tamaños pequeños de semillas/secretos en gVisor de Google permitieron a un atacante remoto calcular una dirección IP local y un identificador por arranque que podría ayudar a rastrear un dispositivo en ciertas circunstancias.
References
  • () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf -

30 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 20:15

Updated : 2025-02-24 12:15


NVD link : CVE-2024-10026

Mitre link : CVE-2024-10026

CVE.ORG link : CVE-2024-10026


JSON object : View

Products Affected

No product.

CWE
CWE-328

Reversible One-Way Hash

CWE-339

Small Seed Space in PRNG