In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "22.1.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "22.1.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "22.2.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "5.13.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "5.13.3"
}
],
"source": "DESCRIPTION"
}
]
}