Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2021-20322
Linux Kernel vulnerability analysis and mitigation

Overview

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was discovered that allows the ability to quickly scan open UDP ports. This vulnerability, identified as CVE-2021-20322, enables an off-path remote user to effectively bypass the source port UDP randomization. The vulnerability was first reported in December 2020 and affects Linux kernel versions through 5.14.21 (CVE Mitre, NVD).

Technical details

The vulnerability exists in the Linux kernel's ICMP error processing mechanism, specifically affecting how the system handles ICMP fragment needed and ICMP redirect packets. The issue has been assigned a CVSS score of 7.4 (HIGH) with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating a network-exploitable vulnerability with high impact on confidentiality and integrity (NetApp Advisory).

Impact

The highest threat from this vulnerability is to confidentiality and possibly integrity, as software that relies on UDP source port randomization is indirectly affected. The vulnerability allows attackers to quickly discover which UDP ports a system is using, making it easier to conduct DNS poisoning attacks against the target system (Debian Security Advisory).

Mitigation and workarounds

The vulnerability was fixed in Linux kernel version 5.15-rc1 through multiple patches that improve the handling of ICMP errors. The fixes include changes to the hash functions used in IPv4 and IPv6 implementations, replacing Jenkins Hash with siphash, and making the exception cache less predictable (Linux Kernel Commit).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management