CVE-2024-10026

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*
cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*

History

31 Jul 2025, 18:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Google
Google gvisor
CPE cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*
References () https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2 - () https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2 - Patch
References () https://github.com/google/gvisor/commit/e54bfde79278cafadedbf73c68ee10cb5982f2af - () https://github.com/google/gvisor/commit/e54bfde79278cafadedbf73c68ee10cb5982f2af - Patch
References () https://github.com/google/gvisor/commit/f956b5ac17ae1f60a4d21999b59ba18c55f86d56 - () https://github.com/google/gvisor/commit/f956b5ac17ae1f60a4d21999b59ba18c55f86d56 - Patch
References () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf - () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf - Exploit, Third Party Advisory, Technical Description
CWE CWE-326
CWE-335

24 Feb 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Un algoritmo hash débil y tamaños pequeños de semillas/secretos en gVisor de Google permitieron a un atacante remoto calcular una dirección IP local y un identificador por arranque que podría ayudar a rastrear un dispositivo en ciertas circunstancias.
References
  • () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf -

30 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 20:15

Updated : 2025-07-31 18:33


NVD link : CVE-2024-10026

Mitre link : CVE-2024-10026

CVE.ORG link : CVE-2024-10026


JSON object : View

Products Affected

google

  • gvisor
CWE
CWE-328

Use of Weak Hash

CWE-339

Small Seed Space in PRNG

CWE-326

Inadequate Encryption Strength

CWE-335

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)