Vulnerability Description
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gvisor | < 20231030.0 |
Related Weaknesses (CWE)
References
- https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2Patch
- https://github.com/google/gvisor/commit/e54bfde79278cafadedbf73c68ee10cb5982f2afPatch
- https://github.com/google/gvisor/commit/f956b5ac17ae1f60a4d21999b59ba18c55f86d56Patch
- https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdfExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2024-10026?
CVE-2024-10026 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a dev...
How severe is CVE-2024-10026?
CVE-2024-10026 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10026?
Check the references section above for vendor advisories and patch information. Affected products include: Google Gvisor.