CVE-2026-23247

Source
https://cve.org/CVERecord?id=CVE-2026-23247
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23247.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23247
Downstream
Published
2026-03-18T10:05:09.353Z
Modified
2026-04-14T03:48:37.895365Z
Summary
tcp: secure_seq: add back ports to TS offset
Details

In the Linux kernel, the following vulnerability has been resolved:

tcp: secure_seq: add back ports to TS offset

This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets")

tcptwrecycle went away in 2017.

Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways.

One of them is to bring back TCP ports in TS offset randomization.

As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23247.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
28ee1b746f493b7c62347d714f58fbf4f70df4f0
Fixed
eae2f14ab2efccdb7480fae7d42c4b0116ef8805
Fixed
46e5b0d7cf55821527adea471ffe52a5afbd9caf
Fixed
165573e41f2f66ef98940cf65f838b2cb575d9d1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
443fac9f2618b93cbc5ab068dc594530236b3a23

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23247.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
6.18.17
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23247.json"