An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityHigh
RequirementsPresent
PrivilegesLow
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityNone
IntegrityHigh
AvailabilityLow
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | PoC | E: U→P | 2.3 → 5.5 |
| 2026-07-21 | nvd | AV: P→N, PR: H→L, UI: A→N, VI: N→H, VA: N→L | 0.0 → 2.3 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| linux | linux_kernel | ≤ 5.6.11 |
| netapp | bootstrap_os | All versions |
| netapp | cloud_volumes_ontap_mediator | All versions |
| netapp | e-series_santricity_os_controller | ≥ 11.0 |
| netapp | h300e_firmware | All versions |
| netapp | h300s_firmware | All versions |
| netapp | h410c_firmware | All versions |
| netapp | h410s_firmware | All versions |
| netapp | h500e_firmware | All versions |
| netapp | h500s_firmware | All versions |
| netapp | h610c_firmware | All versions |
| netapp | h610s_firmware | All versions |
| netapp | h615c_firmware | All versions |
| netapp | h700e_firmware | All versions |
| netapp | h700s_firmware | All versions |
| netapp | solidfire_\&_hci_management_node | All versions |
| netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | All versions |
Published: 2022-02-26