CVE-2026-19735
Received Received - Intake

TCP ISN Predictable Due to Failed Entropy Initialization

Vulnerability report for CVE-2026-19735, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The RFC 6528 initial-sequence-number implementation in subsys/net/ip/tcp.c derived every TCP ISN from SHA-256(unique_key || four-tuple) plus a uptime-derived offset, where unique_key is a 128-bit secret filled once by sys_csrand_get(). The return value of that call was discarded and the once guard was latched to true even when the call failed. Because sys_csrand_get() leaves the destination buffer untouched on failure (it deliberately propagates the entropy-driver error rather than filling the buffer), a single failed call left unique_key as its all-zero BSS content for the remainder of the boot, with no retry, no log message and no fallback. A failure of the cryptographic random source is required to reach the weak state β€” for example -ENODEV/-EIO from the entropy driver in subsys/random/random_entropy_device.c (the in-tree comment notes that the hardware RNG "might still be gathering entropy during early boot situations"), or psa_generate_random() failing in subsys/random/random_psa.c when PSA crypto is not initialised or is backed by a Bluetooth-HCI entropy device that is not yet up. The first TCP connection is what triggers key generation, so a remote peer that reaches a listening port immediately after boot, or that can provoke a reboot, has indirect influence over whether generation coincides with that window. tcp_init_isn() is called for every passive open in tcp_conn_new() and every active open in net_tcp_connect(), so the poisoned key governs all TCP connections for that boot. With an all-zero key the ISN becomes a public function of the connection four-tuple plus a device-wide time offset. An off-path attacker can compute the hash term offline for any four-tuple and recover the shared time offset from a single observed ISN, after which the ISN the device will pick for other four-tuples is predictable. That defeats exactly the protection RFC 6528 provides: blind TCP connection spoofing against peers that trust the source address, and blind data injection into or reset of connections whose four-tuple can be guessed. Devices whose entropy source never errors were never in the weak state. The fix moves key generation into a single guarded helper that latches only on success, logs the error otherwise, and makes tcp_init_isn() fall back to sys_rand32_get() β€” the behaviour already used when CONFIG_NET_TCP_ISN_RFC6528 is disabled β€” instead of hashing with a known-constant key.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Zephyr RTOS TCP implementation where the Initial Sequence Number (ISN) secret key generation could fail silently. If the random key generation function sys_csrand_get() fails, the system ignores the error and leaves the key as all zeros for the entire boot cycle. This makes the ISN predictable based on the connection four-tuple, violating RFC 6528 which requires cryptographically secure ISN generation.

Detection Guidance

Detecting this vulnerability requires checking if the Zephyr RTOS TCP stack is using a predictable ISN due to a failed random key generation. Monitor logs for entropy source failures during boot, particularly errors from sys_csrand_get() or psa_generate_random(). Check if the system is running affected Zephyr versions (3.7.0 to 4.4.2) and verify if the fix (commit 700888e3ecff8474f4fe7dfa8782b8869053222b) is applied.

Impact Analysis

An attacker could exploit this to predict TCP ISNs, enabling blind TCP connection spoofing or data injection into existing connections. This could allow unauthorized access to connections or reset active sessions. The impact is limited to devices where the entropy source fails during boot.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality and integrity requirements in GDPR and HIPAA. Predictable ISNs undermine secure communication channels, potentially exposing sensitive data.

Mitigation Strategies

Update Zephyr RTOS to version 4.5.0 or later to apply the fix for predictable TCP ISNs. Ensure the entropy source is functioning properly during boot to prevent sys_csrand_get() failures. Monitor logs for entropy driver errors or failures in cryptographic random source initialization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19735. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart