A network-adjacent attacker can send packets addressed to a host's VPN
tunnel address over the physical interface. Because Linux uses the weak
host model by default, the host replies, which lets the attacker infer
the tunnel address, confirm active connections and eventually inject
into the tunneled TCP stream.

No upstream kernel fix exists. Ubuntu has the fix deferred since
2019-12-13, Debian does not track it against the kernel, and Red Hat
scopes it to openvpn:

  https://ubuntu.com/security/CVE-2019-14899
  https://security-tracker.debian.org/tracker/CVE-2019-14899

Record it unpatched so it stays visible rather than excluded.

CC: Paul Barker <[email protected]>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <[email protected]>
---
v4:
- use the review's comment and status wording; drop the mitigation
  discussion

v3: 
https://lore.kernel.org/openembedded-core/[email protected]/

 meta/recipes-kernel/linux/cve-exclusion.inc | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc 
b/meta/recipes-kernel/linux/cve-exclusion.inc
index d27d7644..b2eb15d0 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -192,3 +192,8 @@ CVE_STATUS[CVE-2025-68195] = "fixed-version: Fixed from 
6.18"
 # Fix https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3
 # Backport 
https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
 CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
+
+# Triaged August 2026 - no upstream fix, Ubuntu fix deferred
+# https://ubuntu.com/security/CVE-2019-14899
+CVE_STATUS[CVE-2019-14899] = "unpatched: Consequence of the default weak host \
+model, no upstream fix"
-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244047): 
https://lists.openembedded.org/g/openembedded-core/message/244047
Mute This Topic: https://lists.openembedded.org/mt/120897557/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to