peter bassill · operator
$ cve CVE-2021-22600 JSON

CVE-2021-22600 KEV

6.6
MEDIUM · CVSS 3.1 · EPSS 6.5% (pctl 94)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-02.

Description

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

Scoring

CVSS6.6 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
EPSS6.53% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-415
On CISA KEVyes — remediate by 2022-05-02
Public exploitnone known
Published2022-01-26
Last modified2026-06-17

CISA KEV

NameLinux Kernel Privilege Escalation Vulnerability
Added2022-04-11
Due2022-05-02
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (20)

VendorProduct
debiandebian linux
linuxlinux kernel
netapp8300
netapp8300 firmware
netapp8700
netapp8700 firmware
netappa400
netappa400 firmware
netappc400
netappc400 firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500s
netapph500s firmware
netapph700s
netapph700s firmware

References

→ the Explorer  ·  watch your stack  ·  NVD