CVE-2021-20322

Updated: 2025-08-20 01:37:13.023109

Description:

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.8
CVSS Version 3.x HIGH 7.4

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.4 HIGH Already Fixed 2024-01-29 08:42:56
CentOS 6 ELS kernel 2.6.32 7.4 HIGH Not Vulnerable 2022-04-13 07:24:10
CentOS 7 ELS kernel 3.10.0 7.4 HIGH Released CLSA-2024:1720468480 2024-07-23 17:33:11
CentOS 8.4 ELS kernel 4.18.0 7.4 HIGH Released CLSA-2023:1686585068 2023-06-13 09:13:44
CentOS 8.5 ELS kernel 4.18.0 7.4 HIGH Released CLSA-2023:1686651204 2023-06-13 09:13:44
CentOS Stream 8 ELS kernel 4.18.0 7.4 HIGH Already Fixed 2024-06-09 11:20:36
CloudLinux 6 ELS kernel 2.6.32 7.4 HIGH Not Vulnerable 2022-12-02 16:07:14
CloudLinux 7 ELS kernel 3.10.0 7.4 HIGH Ignored 2025-01-10 22:43:41 CL7 support is limited
Oracle Linux 6 ELS kernel 2.6.32 7.4 HIGH Not Vulnerable 2022-12-02 16:07:14
RHEL 7 ELS kernel 3.10.0 7.4 HIGH Released CLSA-2025:1750353839 2025-06-20 00:28:23
Total: 13