Improved Seeding and Hashing In gVisor
Vulnerability Description
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10026
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Amit Klein (Hebrew University of Jerusalem)
- Inon Kaplan (Independent researcher)
- Ron Even (Independent researcher)
References
- https://github.com/google/gvisor/commit/f956b5ac17ae1f60a4d21999b59ba18c55f86d56
- https://github.com/google/gvisor/commit/e54bfde79278cafadedbf73c68ee10cb5982f2af
- https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2
- https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf
More from Google
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.