CVE-2021-22600 is a double free vulnerability in the Linux kernel's packet_set_ring() function, affecting Debian, Linux, and NetApp products. This flaw allows a local user to escalate privileges or cause a denial of service through crafted syscalls. With a CVSS score of 7.0 (HIGH), it has high impact on confidentiality, integrity, and availability, but requires low privileges and has high attack complexity. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:8300_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:8700_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:a400_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:* | ||
>= 4.14.175, < 4.14.259CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-22600
Feb 8, 2022Multiple Linux kernel vulnerabilities (CVE-2021-4154, CVE-2021-22600, CVE-2022-0185)
Feb 4, 2022Multiple Linux kernel vulnerabilities (CVE-2021-4154, CVE-2021-22600, CVE-2022-0185)
Feb 2, 2022Double Free in net/packet/af_packet.c leading to priviledge escalation
Jan 11, 2022kernel: double free in packet_set_ring() in net/packet/af_packet.c
Dec 15, 2021