Home / Early Warning / Cybersecurity Highlights / A flaw in TCP implementation threatens users

A flaw in TCP implementation threatens users

08/10/2016

A flaw in TCP implementation in Linux kernel 3.6 and newer might allow malware injection or traffic hijacking. This kernel version is widely used, affecting Android devices and Smart TVs.

The vulnerability  allows guessing TCP sequence number using only IP addresses from both sides, allowing redirecting traffic using an spoofed IP without an MITM scheme. Besides, it can be used to downgrade HTTP connection, reducing security for users.