Junglewise Threat Intelligence

CVE-2021-22600: Linux Kernel Privilege Escalation Vulnerability

CVE-2021-22600 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2022-04-11

Technologies: Linux Kernel. Vendors: Linux, NetApp.

Executive brief

A double-free vulnerability exists in the packet_set_ring() function within net/packet/af_packet.c of the Linux Kernel. A local attacker can exploit this flaw via crafted syscalls to achieve privilege escalation or cause a denial-of-service (DoS) condition.

Affected products

  • Linux Linux Kernel up to (excluding) 5.4.168, 5.10.88, 5.15.11, 5.16.x
  • NetApp ONTAP Select Deploy

Timeline

  • 2022-04-11: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog
  • 2022-04-11: disclosed

Related threats