Researchers Moshe Kol, Amit Klein, and Yossi Gilad demonstrated that Linux systems using the pre-5.18 TCP source-port selection algorithm could be remotely fingerprinted by a hostile website. By inducing and detecting collisions in a per-device-keyed, 256-entry source-port counter table, an attacker could derive a persistent per-boot identifier in roughly 10,000 connection attempts and about ten seconds. The identifier could link activity across browsers, private-browsing sessions, websites, containers, IPv4/IPv6 networks, and in some cases VPNs.
The tracking identifier generally persisted until reboot, while NAT port rewriting and Tor could limit the technique. Following coordinated disclosure, Linux 5.18 added mitigations: time-varying hash input, randomized counter increments, and expansion of the counter table to 65,536 entries, making collision discovery and practical remote fingerprinting substantially harder.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Moshe Kol, Amit Klein, and Yossi Gilad submitted research describing how hash collisions in Linux's TCP source-port selection can generate a per-boot device identifier. They reported that a hostile website could use the technique to track affected Linux devices across browsers, privacy modes, containers, and some network configurations.
The Linux kernel team introduced a security patch mitigating the tracking technique. The fixes added time-varying hash input, randomized counter increments, and expanded the counter table to 65,536 entries; the patch set was merged into Linux 5.18 at release candidate 6.
A patch set to address the TCP source-port fingerprinting issue was initially posted without a public explanation, which was delayed due to the research paper's publication requirements.
A patch by Eric Dumazet introduced the affected TCP source-port selection mechanism in Linux kernel 5.12. The pre-fix design used a 256-entry counter table and a boot-time random key in its hash calculation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
lwn.net
Open sourcearxiv.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.