CVE-2024-10026

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*
cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-30 20:15

Updated : 2025-07-31 18:33


NVD link : CVE-2024-10026

Mitre link : CVE-2024-10026

CVE.ORG link : CVE-2024-10026


JSON object : View

Products Affected

google

  • gvisor
CWE
CWE-328

Use of Weak Hash

CWE-339

Small Seed Space in PRNG

CWE-326

Inadequate Encryption Strength

CWE-335

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)