CVE-2026-23247: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets") tcp_tw_recycle went away in 2017. Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways. One of them is to bring back TCP ports in TS offset randomization. As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset.
Affected products
- Linux Linux Kernel: after 4.11, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.7 (fixed in 6.19.7); version 4.10.14 only; version 4.11 only; version 7.0 only
Published 2026-03-18. Last modified 2026-06-19.