Weaknesses in the generation of TCP/UDP source ports and some other header values in Googles gVisor allowed them to be predicted by an external attacker in some circumstances.
The product uses a scheme that generates numbers or identifiers that are more predictable than required.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Gvisor | * | 20231030.0 (excluding) | |
| Gvisor | 20231106.0 (including) | 20231106.0 (including) | |
| Golang-gvisor-gvisor | Ubuntu | oracular | * | 
| Golang-inet-netstack | Ubuntu | oracular | * |