CVE-2024-10603

Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*
cpe:2.3:a:google:gvisor:20231106.0:*:*:*:*:*:*:*

History

29 Jul 2025, 18:33

Type Values Removed Values Added
First Time Google
Google gvisor
References () https://github.com/google/gvisor/commit/5d2bf2546805afa09a6f6d9b23ec267823e32205 - () https://github.com/google/gvisor/commit/5d2bf2546805afa09a6f6d9b23ec267823e32205 - Patch
References () https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2 - () https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2 - Patch
References () https://github.com/google/gvisor/commit/cbdb2c61b1f753834cedf2ebe68cbc335dadca52 - () https://github.com/google/gvisor/commit/cbdb2c61b1f753834cedf2ebe68cbc335dadca52 - Patch
References () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf - () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf - Exploit, Third Party Advisory, Mitigation, Technical Description
CPE cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*
cpe:2.3:a:google:gvisor:20231106.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

24 Feb 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Las debilidades en la generación de puertos de origen TCP/UDP y algunos otros valores de encabezado en gVisor de Google permitieron que un atacante externo pudiera predecirlos en algunas circunstancias.
References
  • () https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf -

30 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 20:15

Updated : 2025-07-29 18:33


NVD link : CVE-2024-10603

Mitre link : CVE-2024-10603

CVE.ORG link : CVE-2024-10603


JSON object : View

Products Affected

google

  • gvisor
CWE
CWE-340

Generation of Predictable Numbers or Identifiers