HIGH

CVE-2021-22600

Linux Linux Kernel 2022-01-26 CVSS v3.1
CVSS
7
KEV

Description

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

Summary dbcve.org

A double-free vulnerability exists in the packet_set_ring() function within net/packet/af_packet.c in the Linux kernel. Local attackers can exploit this through crafted syscalls to trigger memory corruption, potentially achieving privilege escalation or causing a denial of service.

Mitigation

Upgrade the Linux kernel to a version beyond the affected releases, or rebuild the kernel applying the fix from commit ec6af094ea28f0f2dda1a6a33b14cd57e36a9755.

Patch Commit

Weakness (CWE)

CWE-415 Double Free

EPSS Score

6.53%
Probability of exploitation in next 30 days
93.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE