CISA KEV · Known exploitedHigh

CVE-2021-22600

Linux Kernel

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

CVSS
7
EPSS
5.87%
92.5% percentile
CISA KEV
Listed
Published
2022.01.26
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability5.87%
Technical severityCVSS 7

Vulnerability overview

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

Affected product and versions

Product
Linux Kernel
Affected versions
unspecified, >= 4.14.175 < 4.14.259, >= 4.19.114 < 4.19.222, >= 5.4.29 < 5.4.168, >= 5.5.14 < 5.10.88, >= 5.11 < 5.15.11, 9.0, 10.0
Fixed versions
4.14.259, 4.19.222, 5.4.168, 5.10.88, 5.15.11

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply updates per vendor instructions.

Due date: 2022.05.02
  1. 1
    Identify

    Confirm that Linux Kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-415
KEV added
2022.04.11
Ransomware use
미확인
CVE-2021-22600 — Linux Kernel | SECUFOCUS NOW