{"api_version":"1","generated_at":"2026-07-23T07:39:08+00:00","cve":"CVE-2014-7284","urls":{"html":"https://cve.report/CVE-2014-7284","api":"https://cve.report/api/cve/CVE-2014-7284.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-7284","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-7284"},"summary":{"title":"CVE-2014-7284","description":"The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-10-13 10:55:08","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://web.archive.org/web/20141002163852/http://secondlookforensics.com/ngro-linux-kernel-bug/","name":"https://web.archive.org/web/20141002163852/http://secondlookforensics.com/ngro-linux-kernel-bug/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Second Look® | Linux Threat Detection & Response | CVE-2014-7284 NGRO Linux Kernel Bug","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3d4405226d27b3a215e4d03cfa51f536244e5de7","name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3d4405226d27b3a215e4d03cfa51f536244e5de7","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2014/10/01/19","name":"http://www.openwall.com/lists/oss-security/2014/10/01/19","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE Request: linux kernel net_get_random_once bug","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/3d4405226d27b3a215e4d03cfa51f536244e5de7","name":"https://github.com/torvalds/linux/commit/3d4405226d27b3a215e4d03cfa51f536244e5de7","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"net: avoid dependency of net_get_random_once on nop patching · torvalds/linux@3d44052 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5","name":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1148788","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1148788","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 1148788 – CVE-2014-7284 kernel: randomness degradation due to bug in net_get_random_once()","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=3d4405226d27b3a215e4d03cfa51f536244e5de7","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=3d4405226d27b3a215e4d03cfa51f536244e5de7","refsource":"MITRE","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-7284","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-7284","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.13.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.14.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.14.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.14.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"7284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"3.14.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T12:47:32.648Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1148788"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5"},{"name":"[oss-security] 20141001 CVE Request: linux kernel net_get_random_once bug","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2014/10/01/19"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://web.archive.org/web/20141002163852/http://secondlookforensics.com/ngro-linux-kernel-bug/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3d4405226d27b3a215e4d03cfa51f536244e5de7"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/torvalds/linux/commit/3d4405226d27b3a215e4d03cfa51f536244e5de7"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-05-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-10-13T07:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1148788"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5"},{"name":"[oss-security] 20141001 CVE Request: linux kernel net_get_random_once bug","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2014/10/01/19"},{"tags":["x_refsource_MISC"],"url":"https://web.archive.org/web/20141002163852/http://secondlookforensics.com/ngro-linux-kernel-bug/"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3d4405226d27b3a215e4d03cfa51f536244e5de7"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/torvalds/linux/commit/3d4405226d27b3a215e4d03cfa51f536244e5de7"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-7284","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1148788","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1148788"},{"name":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5"},{"name":"[oss-security] 20141001 CVE Request: linux kernel net_get_random_once bug","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2014/10/01/19"},{"name":"https://web.archive.org/web/20141002163852/http://secondlookforensics.com/ngro-linux-kernel-bug/","refsource":"MISC","url":"https://web.archive.org/web/20141002163852/http://secondlookforensics.com/ngro-linux-kernel-bug/"},{"name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=3d4405226d27b3a215e4d03cfa51f536244e5de7","refsource":"CONFIRM","url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=3d4405226d27b3a215e4d03cfa51f536244e5de7"},{"name":"https://github.com/torvalds/linux/commit/3d4405226d27b3a215e4d03cfa51f536244e5de7","refsource":"CONFIRM","url":"https://github.com/torvalds/linux/commit/3d4405226d27b3a215e4d03cfa51f536244e5de7"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-7284","datePublished":"2014-10-13T10:00:00.000Z","dateReserved":"2014-10-01T00:00:00.000Z","dateUpdated":"2024-08-06T12:47:32.648Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-10-13 10:55:08","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.1:*:*:*:*:*:*:*","matchCriteriaId":"531009EC-C86D-4017-BEF1-924674268F6B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.2:*:*:*:*:*:*:*","matchCriteriaId":"6FBC6289-598B-429E-94CE-5D98B120B9AA"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.3:*:*:*:*:*:*:*","matchCriteriaId":"4D5B7BFA-81AC-424C-A6BC-32CBBDCA6148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.4:*:*:*:*:*:*:*","matchCriteriaId":"0551AB9C-1D52-4A7B-99F8-357FB90067D1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.5:*:*:*:*:*:*:*","matchCriteriaId":"B043E843-877A-4966-9505-C57D69D54C18"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.6:*:*:*:*:*:*:*","matchCriteriaId":"70EED6A5-49BB-4204-94B5-3A48CE61811B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.7:*:*:*:*:*:*:*","matchCriteriaId":"CA4749C0-10E1-43A1-A2DE-D260B513AC02"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.8:*:*:*:*:*:*:*","matchCriteriaId":"0026BE0A-C87B-4EDD-8AF5-67C05F2A465D"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.9:*:*:*:*:*:*:*","matchCriteriaId":"E42C27D8-8ED6-4403-AAAA-8F6C06910FA9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.10:*:*:*:*:*:*:*","matchCriteriaId":"9A4A60F8-2F0B-4872-B3C5-45443EA71F8A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.13.11:*:*:*:*:*:*:*","matchCriteriaId":"90A077DF-5648-45F7-A078-294E81834279"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.14.1:*:*:*:*:*:*:*","matchCriteriaId":"742641DA-1CAE-4156-95F3-367793713696"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.14.2:*:*:*:*:*:*:*","matchCriteriaId":"A3EBDD96-92E4-429F-A697-14364CF68EEC"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.14.3:*:*:*:*:*:*:*","matchCriteriaId":"998AC0EF-FC56-4F8F-B9B2-1A45C80C2231"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:3.14.4:*:*:*:*:*:*:*","matchCriteriaId":"DF6C7930-913B-4B82-BF14-CD9A0E8A968F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"7284","Ordinal":"1","Title":"CVE-2014-7284","CVE":"CVE-2014-7284","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"7284","Ordinal":"1","NoteData":"The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values.","Type":"Description","Title":"CVE-2014-7284"},{"CveYear":"2014","CveId":"7284","Ordinal":"2","NoteData":"2014-10-13","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"7284","Ordinal":"3","NoteData":"2014-10-13","Type":"Other","Title":"Modified"}]}}}