CVE-2021-20322
HighA flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.
CVSS 3.1 score
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness type
CWE-330CVE-2021-20322 is classified as CWE-330
See CWE-330 on MITRE CWE for full details on this weakness type.
References
The following references provide additional information about CVE-2021-20322 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
Issue Tracking Third Party Advisory
-
Mailing List Third Party Advisory
-
Third Party Advisory
-
Debian Securityhttps://www.debian.org/security/2022/dsa-5096Third Party Advisory
-
Third Party Advisory
-
PatchKernel patch commithttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?h=v5.15-rc6&id=4785305c05b25a242e5314cc821f54ade4c18810
-
PatchKernel patch commithttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?h=v5.15-rc6&id=6457378fe796815c973f631a1904e147d6ee33b1
-
PatchKernel patch commithttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv4/route.c?h=v5.15-rc6&id=67d6d681e15b578c1725bad8ad079e05d1c48a8e
Frequently asked questions
-
What is CVE-2021-20322?
CVE-2021-20322 is a High severity Linux kernel vulnerability with a CVSS score of 7.4 out of 10 . CVE-2021-20322 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2021-20322?
CVE-2021-20322 has a CVSS score of 7.4 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N. -
Is there a patch available for CVE-2021-20322?
No patch is currently available for CVE-2021-20322. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2021-20322 actively exploited?
No — CVE-2021-20322 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.