CVE-2011-3188

critical
Published 2012-05-24 ยท Modified 2026-04-29
CVSS v3
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.1

Description

The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.

Predictions

Exploit likelihood
94%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

linux Linux kernel Affected 1 release
VersionStatusFixed in
โ€” Affected 3.1
redhat Red Hat Affected 1 release
VersionStatusFixed in
4.0 Affected โ€”

Application impact

VendorProductVersionsFixed
f5arx{"startIncluding":"6.0.0","endIncluding":"6.4.0"}
f5big-ip_access_policy_manager{"startIncluding":"10.1.0","endIncluding":"10.2.4"}
f5big-ip_analytics{"startIncluding":"11.0.0","endIncluding":"11.1.0"}
f5big-ip_application_security_manager{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5big-ip_edge_gateway{"startIncluding":"10.1.0","endIncluding":"10.2.4"}
f5big-ip_global_traffic_manager{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5big-ip_link_controller{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5big-ip_local_traffic_manager{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5big-ip_protocol_security_module{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5big-ip_wan_optimization_manager{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5big-ip_webaccelerator{"startIncluding":"10.0.0","endIncluding":"10.2.4"}
f5enterprise_manager{"startIncluding":"2.1.0","endIncluding":"2.3.0"}
f5enterprise_manager3.0.0
f5firepass{"startIncluding":"6.0.0","endIncluding":"6.1.0"}
f5firepass7.0.0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.