CVE-2024-10026

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
30/01/2025
Last modified:
31/07/2025

Description

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:* 20231030.0 (excluding)
cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:* 20231106.0 (including) 20231204.0 (excluding)