CVE-2021-20322Use of Insufficiently Random Values in Kernel

Severity
7.4HIGHNVD
EPSS
0.1%
top 66.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateFeb 19

Description

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages8 packages

Debianlinux/linux_kernel< 5.10.70-1+3
Ubuntulinux/linux_kernel< 4.15.0-167.175
NVDlinux/linux_kernel5.14.21
CVEListV5linux/linux_kernelkernel 5.15-rc1

Also affects: Debian Linux 10.0, 9.0, Fedora 34

Patches

🔴Vulnerability Details

4
GHSA
GHSA-x37m-35qq-p254: A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the abi2022-02-19
OSV
CVE-2021-20322: A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the abi2022-02-18
CVEList
CVE-2021-20322: A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the abi2022-02-18
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2022-02-03

📋Vendor Advisories

4
Microsoft
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw all2022-02-08
Ubuntu
Linux kernel vulnerabilities2022-02-03
Red Hat
kernel: new DNS Cache Poisoning Attack based on ICMP fragment needed packets replies2021-08-26
Debian
CVE-2021-20322: linux - A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP ...2021
CVE-2021-20322 — Use of Insufficiently Random Values | cvebase