CVE-2021-20322

NameCVE-2021-20322
DescriptionA flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2843-1, DLA-2941-1, DSA-5096-1, ELA-535-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)jessie, jessie (lts)3.16.84-1vulnerable
stretch (security)4.9.320-2fixed
stretch (lts), stretch4.9.320-3fixed
buster4.19.249-2fixed
buster (security)4.19.289-2fixed
bullseye5.10.197-1fixed
bullseye (security)5.10.191-1fixed
bookworm6.1.55-1fixed
bookworm (security)6.1.52-1fixed
trixie6.5.10-1fixed
sid6.5.13-1fixed
linux-4.19 (PTS)stretch (security)4.19.232-1~deb9u1fixed
stretch (lts), stretch4.19.289-2~deb9u1fixed
linux-4.9 (PTS)jessie, jessie (lts)4.9.303-1~deb8u3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcejessie(unfixed)end-of-life
linuxsourcestretch4.9.290-1DLA-2843-1
linuxsourcebuster4.19.232-1DSA-5096-1
linuxsourcebullseye5.10.70-1
linuxsource(unstable)5.14.6-1
linux-4.19sourcestretch4.19.232-1~deb9u1DLA-2941-1
linux-4.9sourcejessie4.9.290-1~deb8u1ELA-535-1

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2014230

Search for package or bug name: Reporting problems