← All CVEs

CVE-2021-22600

medium · 6.6Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-11Remediation due 2022-05-02

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

6.6
CVSS
6.1%
EPSS (exploit prob.)
93rd
EPSS percentile
2022-01-26
Published

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H

Weaknesses

CWE-415

Affected products

VendorProductAffected versions
netapp8300_firmwareall versions
netapp8300all versions
netapp8700_firmwareall versions
netapp8700all versions
netappa400_firmwareall versions
netappa400all versions
netappc400_firmwareall versions
netappc400all versions
linuxlinux_kernel>= 4.14.175, < 4.14.259
linuxlinux_kernel>= 4.19.114, < 4.19.222
linuxlinux_kernel>= 5.4.29, < 5.4.168
linuxlinux_kernel>= 5.5.14, < 5.10.88
linuxlinux_kernel>= 5.11, < 5.15.11
debiandebian_linux9.0
debiandebian_linux10.0
netapph410c_firmwareall versions
netapph410call versions
netapph300s_firmwareall versions
netapph300sall versions
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph410s_firmwareall versions
netapph410sall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-22600