CVE-2021-22600
medium · 6.6Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-04-11Remediation due 2022-05-02
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
6.6
CVSS
6.1%
EPSS (exploit prob.)
93rd
EPSS percentile
2022-01-26
Published
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
Weaknesses
CWE-415
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| netapp | 8300_firmware | all versions |
| netapp | 8300 | all versions |
| netapp | 8700_firmware | all versions |
| netapp | 8700 | all versions |
| netapp | a400_firmware | all versions |
| netapp | a400 | all versions |
| netapp | c400_firmware | all versions |
| netapp | c400 | all versions |
| linux | linux_kernel | >= 4.14.175, < 4.14.259 |
| linux | linux_kernel | >= 4.19.114, < 4.19.222 |
| linux | linux_kernel | >= 5.4.29, < 5.4.168 |
| linux | linux_kernel | >= 5.5.14, < 5.10.88 |
| linux | linux_kernel | >= 5.11, < 5.15.11 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| netapp | h410c_firmware | all versions |
| netapp | h410c | all versions |
| netapp | h300s_firmware | all versions |
| netapp | h300s | all versions |
| netapp | h500s_firmware | all versions |
| netapp | h500s | all versions |
| netapp | h700s_firmware | all versions |
| netapp | h700s | all versions |
| netapp | h410s_firmware | all versions |
| netapp | h410s | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://security.netapp.com/advisory/ntap-20230110-0002/
- https://www.debian.org/security/2022/dsa-5096
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://security.netapp.com/advisory/ntap-20230110-0002/
- https://www.debian.org/security/2022/dsa-5096
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22600
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-22600