CVE-2021-22600
Last modified
CVE-2021-22600 is a high-severity vulnerability rated 7/10 on the CVSS scale. A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755. CISA has confirmed active exploitation in the wild. EPSS estimates a 5.92% chance of exploitation in the next 30 days.
Description
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | 8300 Firmware | All versions |
| Netapp | 8700 Firmware | All versions |
| Netapp | A400 Firmware | All versions |
| Netapp | C400 Firmware | All versions |
| Linux | Linux Kernel | >= 4.14.175, < 4.14.259 |
| Linux | Linux Kernel | >= 4.19.114, < 4.19.222 |
| Linux | Linux Kernel | >= 5.4.29, < 5.4.168 |
| Linux | Linux Kernel | >= 5.5.14, < 5.10.88 |
| Linux | Linux Kernel | >= 5.11, < 5.15.11 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
References
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230110-0002/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230110-0002/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22600US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-22600?
How severe is CVE-2021-22600?
How do I fix CVE-2021-22600?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22571A local attacker could read files from some other users' SA3…5.5
- CVE-2021-22572On unix-like systems, the system temporary directory is shar…5.5
- CVE-2021-22573The vulnerability is that IDToken verifier does not verify i…7.3
- CVE-2021-2258Vulnerability in the Oracle Projects product of Oracle E-Bus…8.1
- CVE-2021-2259Vulnerability in the Oracle Payables product of Oracle E-Bus…8.1
- CVE-2021-2260Vulnerability in the Oracle Human Resources product of Oracl…8.1
- CVE-2021-2261Vulnerability in the Oracle Lease and Finance Management pro…8.1
- CVE-2021-2262Vulnerability in the Oracle Purchasing product of Oracle E-B…8.1
- CVE-2021-2263Vulnerability in the Oracle Sourcing product of Oracle E-Bus…8.1
- CVE-2021-22636 Texas Instruments TI-RTOS, when configured to use Hea…7.8
- CVE-2021-22637Multiple stack-based buffer overflow issues have been identi…7.8
- CVE-2021-22638Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a…7.8
Are you affected by CVE-2021-22600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
