CVE-2024-10603

MEDIUM

Google gVisor - Info Disclosure

Title source: llm
STIX 2.1

Description

Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.

Scores

CVSS v3 5.3
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-340
Status published
Products (2)
google/gvisor 20231106.0
google/gvisor < 20231030.0
Published Jan 30, 2025
Tracked Since Feb 18, 2026