CVE-2021-22600
Last modified
CVE-2021-22600 is a high-severity vulnerability rated 7/10 on the CVSS scale. A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755. CISA has confirmed active exploitation in the wild. EPSS estimates a 5.92% chance of exploitation in the next 30 days.
Description
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | 8300 Firmware | All versions |
| Netapp | 8700 Firmware | All versions |
| Netapp | A400 Firmware | All versions |
| Netapp | C400 Firmware | All versions |
| Linux | Linux Kernel | >= 4.14.175, < 4.14.259 |
| Linux | Linux Kernel | >= 4.19.114, < 4.19.222 |
| Linux | Linux Kernel | >= 5.4.29, < 5.4.168 |
| Linux | Linux Kernel | >= 5.5.14, < 5.10.88 |
| Linux | Linux Kernel | >= 5.11, < 5.15.11 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
References
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230110-0002/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230110-0002/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22600US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-22600?
How severe is CVE-2021-22600?
How do I fix CVE-2021-22600?
Are you affected by CVE-2021-22600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
