Security readout for executives and security teams
CVE-2019-10638 is a Linux kernel privacy weakness. Older kernels could generate IP ID values for UDP or ICMP traffic in a way that lets an attacker correlate or track a device. The described attack can be triggered through a crafted web page using WebRTC or gQUIC, but the sources do not show system takeover or active exploitation. Exposure is most likely on Linux systems running kernels older than 5.1.7 or vendor kernels that had not received the corresponding security update. End-user Linux browsers with WebRTC or gQUIC-capable traffic are relevant to the described scenario. Treat this as a moderate privacy and tracking risk, not a confirmed remote compromise issue. Patch through normal kernel maintenance, with higher priority for Linux desktops, browsers, and externally exposed user environments. Mitigation focus: Apply Linux kernel security updates from the relevant distribution vendor.; Verify the kernel includes the upstream fix or vendor backport.; Prioritize internet-browsing Linux endpoints and shared NAT environments..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-10638 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- DSA-4495CVE reference · vendor-advisory, x_refsource_DEBIAN
- 20190812 [SECURITY] [DSA 4495-1] linux security updateCVE reference · mailing-list, x_refsource_BUGTRAQ
- 20190813 [SECURITY] [DSA 4497-1] linux security updateCVE reference · mailing-list, x_refsource_BUGTRAQ
- DSA-4497CVE reference · vendor-advisory, x_refsource_DEBIAN
- [debian-lts-announce] 20190814 [SECURITY] [DLA 1884-1] linux security updateCVE reference · mailing-list, x_refsource_MLIST
- [debian-lts-announce] 20190814 [SECURITY] [DLA 1885-1] linux-4.9 security updateCVE reference · mailing-list, x_refsource_MLIST
- USN-4117-1CVE reference · vendor-advisory, x_refsource_UBUNTU
- USN-4114-1CVE reference · vendor-advisory, x_refsource_UBUNTU
- USN-4115-1CVE reference · vendor-advisory, x_refsource_UBUNTU
- USN-4116-1CVE reference · vendor-advisory, x_refsource_UBUNTU
- USN-4118-1CVE reference · vendor-advisory, x_refsource_UBUNTU
- RHSA-2019:3309CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:3517CVE reference · vendor-advisory, x_refsource_REDHAT
- 20191108 [slackware-security] Slackware 14.2 kernel (SSA:2019-311-01)CVE reference · mailing-list, x_refsource_BUGTRAQ
- https://www.oracle.com/security-alerts/cpuApr2021.htmlCVE reference · x_refsource_MISC
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.8CVE reference · x_refsource_MISC
- https://github.com/torvalds/linux/commit/355b98553789b646ed97ad801a619ff898471b92CVE reference · x_refsource_MISC
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=355b98553789b646ed97ad801a619ff898471b92CVE reference · x_refsource_MISC
- https://arxiv.org/pdf/1906.10478.pdfCVE reference · x_refsource_MISC
- https://github.com/torvalds/linux/commit/55f0fc7a02de8f12757f4937143d8d5091b2e40bCVE reference · x_refsource_MISC
- https://github.com/torvalds/linux/commit/df453700e8d81b1bdafdf684365ee2b9431fb702CVE reference · x_refsource_MISC
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=df453700e8d81b1bdafdf684365ee2b9431fb702CVE reference · x_refsource_MISC
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.7CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
