---
id: CVE-2021-20322
title: >-
  A flaw in the processing of received ICMP errors (ICMP fragment needed and
  ICMP redirect) in the Linux kernel functionality was found to allow the
  ability to quickly scan open UDP ports
summary: >-
  A flaw in the processing of received ICMP errors (ICMP fragment needed and
  ICMP redirect) in the Linux kernel functionality was found to allow the
  ability to quickly scan open UDP ports. This flaw allows an off-path remote
  user to effect…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-330
  - CWE-330
vendor: netapp
product: active_iq_unified_manager
affected:
  - linux_kernel <= 5.14.21
  - fedora = 34
  - debian_linux = 9.0
  - debian_linux = 10.0
  - active_iq_unified_manager
  - 'e-series_santricity_os_controller >= 11.0, <= 11.70.1'
  - 'solidfire,_enterprise_sds_&_hci_storage_node'
  - solidfire_&_hci_management_node
  - fas_baseboard_management_controller_firmware
  - aff_baseboard_management_controller_firmware
  - aff_a700s_firmware
  - h700s_firmware
  - h700e_firmware
  - h500s_firmware
  - h410s_firmware
  - h500e_firmware
  - h300e_firmware
  - h300s_firmware
  - hci_compute_node_firmware
  - communications_cloud_native_core_binding_support_function = 22.1.3
  - communications_cloud_native_core_network_exposure_function = 22.1.1
  - communications_cloud_native_core_policy = 22.2.0
published: '2022-02-18'
updated: '2026-07-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-20322'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2014230'
    label: secalert@redhat.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?h=v5.15-rc6&id=4785305c05b25a242e5314cc821f54ade4c18810
    label: secalert@redhat.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?h=v5.15-rc6&id=6457378fe796815c973f631a1904e147d6ee33b1
    label: secalert@redhat.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv4/route.c?h=v5.15-rc6&id=67d6d681e15b578c1725bad8ad079e05d1c48a8e
    label: secalert@redhat.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv6/route.c?h=v5.15-rc6&id=a00df2caffed3883c341d5685f830434312e4a43
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20220303-0002/'
    label: secalert@redhat.com
  - url: 'https://www.debian.org/security/2022/dsa-5096'
    label: secalert@redhat.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2014230'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?h=v5.15-rc6&id=4785305c05b25a242e5314cc821f54ade4c18810
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?h=v5.15-rc6&id=6457378fe796815c973f631a1904e147d6ee33b1
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv4/route.c?h=v5.15-rc6&id=67d6d681e15b578c1725bad8ad079e05d1c48a8e
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/ipv6/route.c?h=v5.15-rc6&id=a00df2caffed3883c341d5685f830434312e4a43
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220303-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5096'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.06902
epssPercentile: 0.93838
ingestedAt: '2026-07-30T16:54:31.147Z'
---

## Overview

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.

## Affected

- `linux_kernel <= 5.14.21`
- `fedora = 34`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `active_iq_unified_manager`
- `e-series_santricity_os_controller >= 11.0, <= 11.70.1`
- `solidfire,_enterprise_sds_&_hci_storage_node`
- `solidfire_&_hci_management_node`
- `fas_baseboard_management_controller_firmware`
- `aff_baseboard_management_controller_firmware`
- `aff_a700s_firmware`
- `h700s_firmware`
- `h700e_firmware`
- `h500s_firmware`
- `h410s_firmware`
- `h500e_firmware`
- `h300e_firmware`
- `h300s_firmware`
- `hci_compute_node_firmware`
- `communications_cloud_native_core_binding_support_function = 22.1.3`
- `communications_cloud_native_core_network_exposure_function = 22.1.1`
- `communications_cloud_native_core_policy = 22.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
