A network-adjacent attacker can send packets addressed to a host's VPN
tunnel address over the physical interface. Because Linux uses the weak
host model by default, the host replies, which lets the attacker infer
the tunnel address, confirm active connections and eventually inject
into the tunneled TCP stream.

No kernel fix exists. The original disclosure states that reverse path
filtering is not a solution because the attack also works over IPv6,
which has no rp_filter at all:

  https://www.openwall.com/lists/oss-security/2019/12/05/1

Kernel-level mitigations were discussed on netdev and the WireGuard list
in December 2019 but nothing was merged; the mitigation that shipped was
a firewall rule added to wg-quick(8) in userspace:

  https://lore.kernel.org/all/[email protected]/

Ubuntu has the issue deferred for every release since 2019-12-13 and
records "No current fix from upstream":

  https://ubuntu.com/security/CVE-2019-14899

Debian does not track it against the kernel source package at all, and
Red Hat scopes it to openvpn rather than the kernel:

  https://security-tracker.debian.org/tracker/CVE-2019-14899
  https://access.redhat.com/security/cve/CVE-2019-14899

The NVD entry carries an unversioned linux_kernel CPE, so no fixed
version can ever match it.

CC: Paul Barker <[email protected]>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <[email protected]>
---
changes in v2:
- split out of the single combined patch, one CVE per patch as requested
- added primary source links (disclosures, distribution trackers, mailing
  list threads, upstream commits) to every commit message
- added the three CVEs with no upstream fix as "unpatched" entries instead
  of leaving them undocumented
- disclosed AI assistance per the contributor guide

v1: 
https://lore.kernel.org/openembedded-core/[email protected]/

 meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc 
b/meta/recipes-kernel/linux/cve-exclusion.inc
index d27d7644..aaba26fe 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -192,3 +192,10 @@ CVE_STATUS[CVE-2025-68195] = "fixed-version: Fixed from 
6.18"
 # Fix https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3
 # Backport 
https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
 CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
+
+# Consequence of the default weak host model, not a specific defect.
+# Mitigation is configuration only: rp_filter for IPv4, or a strong host
+# model rule such as the one wg-quick(8) installs, which also covers IPv6.
+# https://www.openwall.com/lists/oss-security/2019/12/05/1
+CVE_STATUS[CVE-2019-14899] = "upstream-wontfix: consequence of the default 
weak \
+host model, no kernel fix exists or is planned, mitigated by firewall 
configuration"
-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242627): 
https://lists.openembedded.org/g/openembedded-core/message/242627
Mute This Topic: https://lists.openembedded.org/mt/120574079/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to