CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's TCP-AO implementation, where uninitialized bytes in standalone TCP responses could be transmitted, potentially leading to information leakage. This issue arises during the construction of TCP responses, specifically when the MAC length is not aligned to a four-byte boundary, allowing sensitive data to be inadvertently exposed. Organizations using Linux systems, particularly those relying on TCP-AO for secure communications, should prioritize addressing this vulnerability to mitigate the risk of data exposure.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP responses with TCP-AO options. The option length carries the actual MAC length, but the TCP header length includes the option rounded up to a four-byte boundary. tcp_ao_hash_hdr() writes the MAC only. Thus, when the MAC length is not four-byte aligned, the one to three bytes after the MAC are left uninitialized and may be transmitted. For the normal TCP-AO hashing mode, those bytes also have to be initialized before computing the MAC. Initialize only the alignment padding in the TCP-AO branches, before hashing the header. Use TCPOPT_NOP, as in the normal TCP-AO output path. This avoids adding work to non-AO TCP responses while preserving a valid authenticated header.