imPC@ndo IT

Tracker / CVE-2021-20322

CVE-2021-20322

High 7.4

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.

Affected products and versions

debian debian_linux
fedoraproject fedora
linux linux_kernel · 4.15 → 4.19.215
linux linux_kernel · 4.20 → 5.4.157
linux linux_kernel · 5.11 → 5.13.14
linux linux_kernel · 5.5 → 5.10.62
netapp active_iq_unified_manager
netapp aff_a700s_firmware
netapp aff_baseboard_management_controller_firmware
netapp e-series_santricity_os_controller · 11.0 → 11.70.1
netapp fas_baseboard_management_controller_firmware
netapp h300e_firmware
netapp h300s_firmware
netapp h410s_firmware
netapp h500e_firmware
netapp h500s_firmware
netapp h700e_firmware
netapp h700s_firmware
netapp hci_compute_node_firmware
netapp solidfire\,_enterprise_sds_\&_hci_storage_node
netapp solidfire_\&_hci_management_node
oracle communications_cloud_native_core_binding_support_function
oracle communications_cloud_native_core_network_exposure_function
oracle communications_cloud_native_core_policy

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References